CVE Vulnerabilities

CVE-2025-0674

Authentication Bypass Using an Alternate Path or Channel

Published: Feb 07, 2025 | Modified: Feb 07, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit this issue by manipulating the endpoint to overwrite any users password within the system. This grants them unauthorized administrative access to protected areas of the application, compromising the devices system security.

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Potential Mitigations

References