Skip to main content

CVE-2023-32328

7.5
HIGHCVSS v3.1 Base Score
0.04%
LOW RiskEPSS (11th percentile)

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957.

Published: 2/7/2024
Modified: 11/3/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.5HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

0.04%LOW Exploitation Risk
11th percentile

This vulnerability has a 0.04% probability of being exploited in the next 30 days, ranking higher than 11% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-319)

CVE-2025-34271CRITICAL 9.8

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network path can intercept credentials in transit. Captured credentials could allow the attacker to authenticate as a cluster node or service account, enabling further unauthorized access, lateral movement, or system compromise.

10/30/2025
CVE-2024-37393HIGH 7.5

Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.

6/10/2024
CVE-2024-25735CRITICAL 9.1

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

3/27/2024
CVE-2023-39245CRITICAL 9.8

DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.

2/15/2024
CVE-2023-39172CRITICAL 9.1

The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.

12/7/2023

Similar SeverityHIGH