A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in an authentication bypass.
The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Xweb_500b_pro_firmware | Copeland | * | 1.12.1 (including) |