7.5

CVE-2022-27558

HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability.

HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Domino Version 12.0.1 Update -
Hcltech ≫ Domino Version 12.0.1 Update fixpack_1
Hcltech ≫ Hcl Inotes Version 12.0.1 Update -
Hcltech ≫ Hcl Inotes Version 12.0.1 Update fixpack_1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.406
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
psirt@hcl.com 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-521 Weak Password Requirements

The product does not require that users should have strong passwords.

https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0100217
Vendor Advisory