Unverified Password Change Vulnerability in ANC Software by ABB
CVE-2024-47784

2.1LOW

Key Information:

Vendor

Abb

Vendor
CVE Published:
30 April 2025

What is CVE-2024-47784?

The ANC software by ABB contains a vulnerability that allows authenticated users to bypass the old password verification step when changing their passwords through the web HMI. This flaw can lead to unauthorized access, as attackers may exploit it to change passwords without the correct old password, thereby compromising user accounts and associated data. It is essential for users to apply available patches and update to versions beyond 1.1.4 to mitigate this risk.

Affected Version(s)

ANC 0 <= 1.1.4

ANC-L 0 <= 1.1.4

ANC-mini 0 <= 1.1.4

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-47784 : Unverified Password Change Vulnerability in ANC Software by ABB