ANC Software Unverified Password Change Vulnerability
Vulnerability
A vulnerability exists in ANC software versions through 1.1.4, allowing authenticated attackers to bypass the old password verification in the password change form via the web HMI. This flaw enables unauthorized password changes.
Impact
Exploitation of this vulnerability allows for unauthorized password changes, potentially leading to account takeover.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
5.2remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
