Description
A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password Modification Endpoint. The manipulation of the argument newPass results in weak password recovery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.
Published: 2026-07-12
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the change_passwd endpoint of H3C NX15 V100R017 allows an attacker to manipulate the newPass argument and trigger a weak password recovery process; the vulnerability is classified as CWE-640, indicating that the reset operation does not enforce strong authentication, enabling an attacker to recover the password from any network-accessible device. The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at this time, although exploitation is possible. The exploit has been made public and could be used, and the vendor has been notified.

Affected Systems

The vulnerability impacts H3C NX15 devices running firmware version V100R017; no other firmware revisions are listed as affected.

Risk and Exploitability

Remote attackers can exploit the exposed /api/login/modify endpoint to reset administrator passwords without proper verification, thereby gaining administrative access. The password recovery mechanism appears permissive, and the exploit is publicly available, indicating that exploitation is possible, although current EPSS indicates it is unlikely. The vulnerability remains a risk until a vendor fix is released. The vulnerability is not listed in CISA KEV.

Generated by OpenCVE AI on August 1, 2026 at 11:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any firmware update that addresses the change_passwd password recovery issue
  • Restrict or disable remote access to the /api/login/modify endpoint until a patch is available
  • Enforce a strong password policy that requires complex credentials for the newPass field
  • Enable logging for password reset attempts and review logs for abnormal activity

Generated by OpenCVE AI on August 1, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password Modification Endpoint. The manipulation of the argument newPass results in weak password recovery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.
Title H3C NX15 Administrator Password Modification Endpoint modify change_passwd password recovery
First Time appeared H3c
H3c nx15
Weaknesses CWE-640
CPEs cpe:2.3:a:h3c:nx15:*:*:*:*:*:*:*:*
Vendors & Products H3c
H3c nx15
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-14T14:39:21.478Z

Reserved: 2026-07-11T09:56:44.847Z

Link: CVE-2026-15479

cve-icon Vulnrichment

Updated: 2026-07-14T14:39:13.380Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:30:05Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password