CVE Vulnerabilities

CVE-2024-37998

Unverified Password Change

Published: Jul 22, 2024 | Modified: Jul 22, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). The password of administrative accounts of the affected applications can be reset without requiring the knowledge of the current password, given the auto login is enabled. This could allow an unauthorized attacker to obtain administrative access of the affected applications.

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Potential Mitigations

References