HIGH

CVE-2023-33243

CVSS v3

8.1

HIGH

EPSS Score

12.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. While storing password hashes instead of cleartext passwords in an application's database generally has become best practice to protect users' passwords in case of a database compromise, this is rendered ineffective when allowing to authenticate using the password hash.

Technical details

Published
6/15/2023
Exploit-DB
EDB-51503

Frequently asked questions

What is CVE-2023-33243?

RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. While storing password hashes instead of cleartext passwords in an application's database generally has become best practice to protect users' passwords in case of a database compromise, this is rendered ineffective when allowing to authenticate using the password hash.

Is CVE-2023-33243 actively exploited?

Active exploitation of CVE-2023-33243 has not been confirmed. The EPSS score is 12.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-33243?

CVE-2023-33243 has a CVSS v3 base score of 8.1 (HIGH severity).

Is CVE-2023-33243 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.