CVE-2017-20235

CRITICAL

ProSoft Technology ICX35-HWC Authentication Bypass

Title source: cna
STIX 2.1

Description

ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the authentication mechanism in affected firmware versions to obtain full administrative access to device configuration and settings.

Scores

CVSS v3 9.1
EPSS 0.0045
EPSS Percentile 36.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (7)
ProSoft Technology/ICX35-HWC Cellular Gateway < 1.0
ProSoft Technology/ICX35-HWC Cellular Gateway < 1.1
ProSoft Technology/ICX35-HWC Cellular Gateway < 1.1d
ProSoft Technology/ICX35-HWC Cellular Gateway < 1.2.x
ProSoft Technology/ICX35-HWC Cellular Gateway < 1.3
ProSoft Technology/ICX35-HWC Cellular Gateway 1.3
prosoft-technology/icx35-hwc_firmware < 1.3
Published Apr 03, 2026
Tracked Since Apr 04, 2026