The eSoft InstaGate EX2 UTM device does not require entry of the old password when changing the admin password, which might allow remote attackers to gain privileges by conducting a CSRF attack, making a password change from an unattended workstation, or other attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Instagate_ex2_utm | Esoft | firmware_3.1.20031001 (including) | firmware_3.1.20031001 (including) |
Instagate_ex2_utm | Esoft | firmware_3.1.20060921 (including) | firmware_3.1.20060921 (including) |
Instagate_ex2_utm | Esoft | firmware_3.1.20070605 (including) | firmware_3.1.20070605 (including) |