Back

HIGH

An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface

Published Oct 17, 2017

Description

An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is authenticated could change a user's password, enabling future access and possible configuration changes.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Oct 17, 2017
Updated Aug 5, 2024
Reserved Aug 30, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a