CWE-620

Unverified Password Change

Parent: CWE-1390 - Weak Authentication

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

78 vulnerabilities with CWE-620
CVE-2019-25653 MEDIUM
Navicat for Oracle 12.1.15 Password Field Denial of Service
CVSS 6.2
CVE-2018-8916 MEDIUM
Synology Diskstation Manager < 6.2-23739 - Password Reset Weakness
CVSS 6.3
CVE-2017-14005 HIGH
ProMinent MultiFLEX M10a - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 78