PT-2026-52838 · Asp · Asp

CVE-2023-20572

·

Published

2026-06-26

·

Updated

2026-06-26

CVSS v4.0

5.6

Medium

VectorAV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ASP (affected versions not specified)
Description An observable timing discrepancy in the ASP allows a privileged attacker to conduct a brute-force attack against the hash message authentication code (HMAC). This could enable the submission of arbitrary messages, potentially resulting in a loss of data integrity. A timing discrepancy occurs when the system takes different amounts of time to process different inputs, which can be used to deduce secret information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-20572

Affected Products

Asp