2 results (0.010 seconds)

CVSS: 8.5EPSS: 0%CPEs: 1EXPL: 0

13 Mar 2025 — A token is created using the username, current date/time, and a fixed AES-128 encryption key, which is the same across all installations. • https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-072-01 • CWE-1391: Use of Weak Credentials •

CVSS: 8.5EPSS: 0%CPEs: 1EXPL: 0

13 Mar 2025 — A flaw exists in the Windows login flow where an AuthContext token can be exploited for replay attacks and authentication bypass. • https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-072-01 • CWE-287: Improper Authentication •