ANC Software Unverified Password Change Vulnerability

Vulnerability

A vulnerability exists in ANC software versions through 1.1.4, allowing authenticated attackers to bypass the old password verification in the password change form via the web HMI. This flaw enables unauthorized password changes.

Impact

Exploitation of this vulnerability allows for unauthorized password changes, potentially leading to account takeover.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.