This issue affects ANC software version 1.1.4 and earlier.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12784 | Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web HMI This issue affects ANC software version 1.1.4 and earlier. |
Wed, 30 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Apr 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web HMI This issue affects ANC software version 1.1.4 and earlier. | |
| Title | Unverified Password Change | |
| Weaknesses | CWE-620 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ABB
Published:
Updated: 2025-04-30T20:04:47.051Z
Reserved: 2024-10-01T07:37:17.076Z
Link: CVE-2024-47784
Updated: 2025-04-30T20:04:42.435Z
Status : Deferred
Published: 2025-04-30T19:15:54.083
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-47784
No data.
OpenCVE Enrichment
No data.
EUVD