Impact
A flaw in the change_passwd endpoint of H3C NX15 V100R017 allows an attacker to manipulate the newPass argument and trigger a weak password recovery process; the vulnerability is classified as CWE-640, indicating that the reset operation does not enforce strong authentication, enabling an attacker to recover the password from any network-accessible device. The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at this time, although exploitation is possible. The exploit has been made public and could be used, and the vendor has been notified.
Affected Systems
The vulnerability impacts H3C NX15 devices running firmware version V100R017; no other firmware revisions are listed as affected.
Risk and Exploitability
Remote attackers can exploit the exposed /api/login/modify endpoint to reset administrator passwords without proper verification, thereby gaining administrative access. The password recovery mechanism appears permissive, and the exploit is publicly available, indicating that exploitation is possible, although current EPSS indicates it is unlikely. The vulnerability remains a risk until a vendor fix is released. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment