Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, including root user, which could lead to privilege escalation. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 17 Mar 2025 09:45:00 +0000


Mon, 17 Mar 2025 08:45:00 +0000


Thu, 10 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-286

Fri, 23 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Nask
Nask ezd Rp
Weaknesses CWE-863
CPEs cpe:2.3:a:nask:ezd_rp:*:*:*:*:*:*:*:*
Vendors & Products Nask
Nask ezd Rp
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 08 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Nask-pib
Nask-pib ezd Rp
CPEs cpe:2.3:a:nask-pib:ezd_rp:*:*:*:*:*:*:*:*
Vendors & Products Nask-pib
Nask-pib ezd Rp
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Aug 2024 11:00:00 +0000

Type Values Removed Values Added
Description Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, including root user, which could lead to privilege escalation. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.
Title Privilege Escalation in EZD RP
Weaknesses CWE-286
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/R:U/V:D/RE:L/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-03-17T08:34:48.839Z

Reserved: 2024-07-30T08:43:01.420Z

Link: CVE-2024-7265

cve-icon Vulnrichment

Updated: 2024-08-08T14:37:01.184Z

cve-icon NVD

Status : Modified

Published: 2024-08-07T11:15:45.757

Modified: 2025-03-17T09:15:11.963

Link: CVE-2024-7265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.