CVE-2023-37503

EUVD-2023-41390
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
HCLCNA
8.1 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
Affected Products (NVD)
VendorProductVersion
hcltechhcl_compass
2.0.0 ≤
𝑥
≤ 2.0.3
hcltechhcl_compass
2.2.0 ≤
𝑥
< 2.2.3
hcltechhcl_compass
2.1.0
𝑥
= Vulnerable software versions