Unverified Password Change Vulnerability in ANC Software by ABB
CVE-2024-47784
2.1LOW
What is CVE-2024-47784?
The ANC software by ABB contains a vulnerability that allows authenticated users to bypass the old password verification step when changing their passwords through the web HMI. This flaw can lead to unauthorized access, as attackers may exploit it to change passwords without the correct old password, thereby compromising user accounts and associated data. It is essential for users to apply available patches and update to versions beyond 1.1.4 to mitigate this risk.
Affected Version(s)
ANC 0 <= 1.1.4
ANC-L 0 <= 1.1.4
ANC-mini 0 <= 1.1.4
References
CVSS V4
Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved