Description
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass.

This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
Published: 2026-07-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unverified password change flaw that allows an attacker to modify a user’s password without proper authentication. Because authentication is bypassed, an attacker can gain full control of the affected account, compromising confidentiality and integrity of the platform data.

Affected Systems

Vimesoft Inc.’s Enterprise Video Platform versions 3.11.0.0 through 3.25.0 (inclusive of 3.11.0.0 and exclusive of 3.25.0) are vulnerable.

Risk and Exploitability

The CVSS score of 9.8 ranks the flaw as critical, while the EPSS score of less than 1% indicates that widespread exploitation has not yet been observed. The vulnerability is not listed in CISA KEV. Likely attack vectors are remote, via the web interface that handles password changes. Anyone with access to the password change endpoint could exploit this weakness. Given the high severity, vendors’ patches or upgrades should be applied as a priority.

Generated by OpenCVE AI on July 31, 2026 at 00:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade Enterprise Video Platform to version 3.25.0 or later.
  • Enforce additional verification such as email or admin approval before allowing password changes.
  • Restrict access to the password change endpoints by implementing role‑based access control and enable audit logging for attempted changes.
  • Check the vendor’s website for the latest security updates and apply any subsequent patches as they become available.

Generated by OpenCVE AI on July 31, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Vimesoft
Vimesoft enterprise Video Platform
Vendors & Products Vimesoft
Vimesoft enterprise Video Platform

Fri, 17 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
Title Improper Authentication in Vimesoft's Enterprise Video Platform
Weaknesses CWE-620
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Vimesoft Enterprise Video Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-17T16:51:32.290Z

Reserved: 2026-06-19T09:01:24.669Z

Link: CVE-2026-12692

cve-icon Vulnrichment

Updated: 2026-07-17T16:51:27.212Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:15:05Z

Weaknesses
  • CWE-620

    Unverified Password Change