Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-2771 | An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords with a minimum length of 6 characters, lacking adequate complexity to resist modern attack techniques such as password spraying or offline password cracking. |
Tue, 20 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Optimizely
Optimizely optimizely Cms |
|
| CPEs | cpe:2.3:a:optimizely:optimizely_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Optimizely
Optimizely optimizely Cms |
Mon, 06 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sat, 04 Jan 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords with a minimum length of 6 characters, lacking adequate complexity to resist modern attack techniques such as password spraying or offline password cracking. | |
| Weaknesses | CWE-521 | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-06T16:59:45.286Z
Reserved: 2025-01-04T00:00:00.000Z
Link: CVE-2025-22390
Updated: 2025-01-06T16:59:39.393Z
Status : Analyzed
Published: 2025-01-04T02:15:07.747
Modified: 2025-05-20T20:10:40.360
Link: CVE-2025-22390
No data.
OpenCVE Enrichment
No data.
EUVD