The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted privileged commands.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ip360 | Tripwire | 7.2.2 (including) | 7.2.2 (including) |
Ip360 | Tripwire | 7.2.4 (including) | 7.2.4 (including) |
Ip360 | Tripwire | 7.2.5 (including) | 7.2.5 (including) |