Authentication Bypass in ProSoft Technology ICX35-HWC Cellular Gateways
CVE-2017-20235

9.3CRITICAL

What is CVE-2017-20235?

ProSoft Technology ICX35-HWC cellular gateways before version 1.3 are susceptible to an authentication bypass vulnerability. This flaw exists in the web user interface, allowing unauthenticated attackers to access administrative functions without presenting valid credentials. By circumventing the authentication safeguards in these affected firmware versions, an attacker could potentially gain full administrative control over device configurations and settings. It is crucial for users of these gateways to implement immediate security measures to protect their systems.

Affected Version(s)

ICX35-HWC Cellular Gateway 0 <= 1.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.