CVE Vulnerabilities

CVE-2007-3787

Published: Jul 15, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The eSoft InstaGate EX2 UTM device does not require entry of the old password when changing the admin password, which might allow remote attackers to gain privileges by conducting a CSRF attack, making a password change from an unattended workstation, or other attacks.

Affected Software

NameVendorStart VersionEnd Version
Instagate_ex2_utmEsoftfirmware_3.1.20031001 (including)firmware_3.1.20031001 (including)
Instagate_ex2_utmEsoftfirmware_3.1.20060921 (including)firmware_3.1.20060921 (including)
Instagate_ex2_utmEsoftfirmware_3.1.20070605 (including)firmware_3.1.20070605 (including)

References