CVE-2017-14005
—CVSS 3.0
8.8 high
EPSS
1%p70
Published
()
Modified
Description
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is authenticated could change a user's password, enabling future access and possible configuration changes.
- Vendors
- prominent
- Products
- multiflex m10a controller firmware
- Weakness
- CWE-620, CWE-640
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.