Lucene search

K
cvelistIcscertCVELIST:CVE-2021-22661
HistoryFeb 26, 2021 - 2:50 p.m.

CVE-2021-22661

2021-02-2614:50:52
CWE-264
icscert
www.cve.org
4
password change
module webpage
knowledge of password
icx35-hwc-a
icx35-hwc-e
version 1.9.62
cve-2021-22661

EPSS

0.001

Percentile

34.6%

Changing the password on the module webpage does not require the user to type in the current password first. Thus, the password could be changed by a user or external process without knowledge of the current password on the ICX35-HWC-A and ICX35-HWC-E (Versions 1.9.62 and prior).

CNA Affected

[
  {
    "product": "ICX35-HWC-A, ICX35-HWC-E",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions 1.9.62 and prior"
      }
    ]
  }
]

EPSS

0.001

Percentile

34.6%

Related for CVELIST:CVE-2021-22661