Description
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is authenticated could change a user's password, enabling future access and possible configuration changes.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-5520 | An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is authenticated could change a user's password, enabling future access and possible configuration changes. |
References
History
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-05T19:13:41.690Z
Reserved: 2017-08-30T00:00:00.000Z
Link: CVE-2017-14005
No data.
Status : Modified
Published: 2017-10-17T22:29:00.260
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-14005
No data.
OpenCVE Enrichment
No data.
EUVD