CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Description
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-50
CVEs mapped to this weakness (309)
page 2 of 16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-43932 | Cri | 0.64 | 9.8 | 0.00 | Jul 7, 2025 | JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header. | ||
| CVE-2025-43931 | Cri | 0.64 | 9.8 | 0.00 | Jul 7, 2025 | flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header. | ||
| CVE-2025-31380 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2025 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Password Recovery Exploitation.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.3.11. | ||
| CVE-2025-22144 | Cri | 0.64 | 9.8 | 0.01 | Jan 13, 2025 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code… | ||
| CVE-2024-11350 | Cri | 0.64 | 9.8 | 0.01 | Jan 8, 2025 | The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password through the adforest_reset_password()… | ||
| CVE-2024-53552 | Cri | 0.64 | 9.8 | 0.01 | Dec 10, 2024 | CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover. | ||
| CVE-2024-48428 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2024 | An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function. | ||
| CVE-2024-8878 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2024 | The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05. | ||
| CVE-2024-38287 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2024 | The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value. | ||
| CVE-2024-38468 | Cri | 0.64 | 9.8 | 0.00 | Jun 16, 2024 | Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API. | ||
| CVE-2024-5404 | Cri | 0.64 | 9.8 | 0.01 | Jun 3, 2024 | An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism. | ||
| CVE-2023-36487 | Cri | 0.64 | 9.8 | 0.01 | Jun 29, 2023 | The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account. | ||
| CVE-2023-30466 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this… | ||
| CVE-2022-45637 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2023 | An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism. | ||
| CVE-2022-47697 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2023 | COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Account takeover. Anyone can reset the password of the admin accounts. | ||
| CVE-2022-47377 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an… | ||
| CVE-2022-3485 | Cri | 0.64 | 9.8 | 0.01 | Dec 12, 2022 | In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device. | ||
| CVE-2022-44004 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password. | ||
| CVE-2022-37300 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2022 | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions… | ||
| CVE-2022-23855 | Cri | 0.64 | 9.8 | 0.02 | Jan 24, 2022 | An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to reset passwords and login as any local account. |
- risk 0.64cvss 9.8epss 0.00
JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.
- risk 0.64cvss 9.8epss 0.00
flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.
- risk 0.64cvss 9.8epss 0.01
Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Password Recovery Exploitation.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.3.11.
- risk 0.64cvss 9.8epss 0.01
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code…
- risk 0.64cvss 9.8epss 0.01
The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password through the adforest_reset_password()…
- risk 0.64cvss 9.8epss 0.01
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
- risk 0.64cvss 9.8epss 0.01
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
- risk 0.64cvss 9.8epss 0.01
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.
- risk 0.64cvss 9.8epss 0.01
The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value.
- risk 0.64cvss 9.8epss 0.00
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.
- risk 0.64cvss 9.8epss 0.01
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.
- risk 0.64cvss 9.8epss 0.01
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this…
- risk 0.64cvss 9.8epss 0.01
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.
- risk 0.64cvss 9.8epss 0.01
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Account takeover. Anyone can reset the password of the admin accounts.
- risk 0.64cvss 9.8epss 0.01
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an…
- risk 0.64cvss 9.8epss 0.01
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.
- risk 0.64cvss 9.8epss 0.01
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to reset passwords and login as any local account.