CVE-2024-47784

LOW

ANC software <1.1.4 - Auth Bypass

Title source: llm
STIX 2.1

Description

Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web HMI This issue affects ANC software version 1.1.4 and earlier.

Scores

CVSS v3 2.6
EPSS 0.0006
EPSS Percentile 17.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-620
Status published
Products (3)
ABB/ANC < 1.1.4
ABB/ANC-L < 1.1.4
ABB/ANC-mini < 1.1.4
Published Apr 30, 2025
Tracked Since Feb 18, 2026