Home
HIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
20200630 (custom) before 20241112
affected
Default status
unaffected
20200630 (custom) before 20241112
affected
Default status
unaffected
20220413 (custom) before 20240919
affected
Default status
unaffected
20230308 (custom) before 20250827
affected
Description
A low-privileged user can bypass account credentials without confirming the user's current authentication state, which may lead to unauthorized privilege escalation.
Problem types
CWE-620 Unverified Password Change
Product status
20200630 (custom) before 20241112
20200630 (custom) before 20241112
20220413 (custom) before 20240919
20230308 (custom) before 20250827
Credits
Joel Aviad Ossi of WebSec B.V reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-022-05