CVE-2024-23580: Hcl Software Dryice Optibot Reset Station

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values.

Affected products

  • Hcl Software Dryice Optibot Reset Station: version 1.0 only; version 2.0 only

Published 2024-05-28. Last modified 2026-06-17.