An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is authenticated could change a user's password, enabling future access and possible configuration changes.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-5520 An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is authenticated could change a user's password, enabling future access and possible configuration changes.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T19:13:41.690Z

Reserved: 2017-08-30T00:00:00

Link: CVE-2017-14005

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-10-17T22:29:00.260

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-14005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses