CWE-620

Unverified Password Change

Parent: CWE-1390 - Weak Authentication

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

88 vulnerabilities with CWE-620
CVE-2023-2297 CRITICAL
Profile Builder < 3.9.0 - Unauthenticated Password Reset via Plaintext Reset Key
CVSS 9.8
CVE-2023-25931 MEDIUM
Medtronic InterStim X and Micro Clinician - Unverified Password Change
CVSS 6.4
CVE-2022-3152 HIGH
phpfusion < 9.10.20 - Unverified Password Change
CVSS 8.8
CVE-2022-2930 HIGH
octoprint/octoprint <1.8.3 - Info Disclosure
CVSS 7.8
CVE-2022-21935 HIGH
Metasys ADS/ADX/OAS <10.1.5, <11.0.2 - Privilege Escalation
CVSS 7.5
CVE-2022-21934 HIGH
Metasys ADS/ADX/OAS <10.1.5, <11.0.2 - Privilege Escalation
CVSS 8.0
CVE-2021-34786 MEDIUM
Cisco BroadWorks CommPilot Application Software 22.0-22.0.2021.09 - Authenticated Unverified Password Change
CVSS 6.5
CVE-2021-34785 MEDIUM
Cisco BroadWorks CommPilot 22.0-22.0.2021.09 Arbitrary Account Deletion & Privilege Escalation
CVSS 6.5
CVE-2021-22773 MEDIUM
EVlink City/EVlink Parking/EVlink Smart Wallbox <R8 V3.4.0.1 - Unve...
CVSS 6.5
CVE-2020-7378 CRITICAL
OpenCRX < 5.0-20200904 - Unauthenticated Unverified Password Change
CVSS 9.1
CVE-2019-25653 MEDIUM
Navicat for Oracle 12.1.15 Password Field Denial of Service
CVSS 6.2
CVE-2018-8916 MEDIUM
Synology DiskStation Manager < 6.2-23739 - Authenticated Unverified Password Change
CVSS 6.3
CVE-2017-14005 HIGH
ProMinent MultiFLEX M10a - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 88