CVE Vulnerabilities

CVE-2023-47577

Insufficiently Protected Credentials

Published: Dec 13, 2023 | Modified: Dec 18, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current password.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Rely-pcie_firmware Relyum 22.2.1 (including) 22.2.1 (including)

Potential Mitigations

References