VYPR

CWE-640

Weak Password Recovery Mechanism for Forgotten Password

BaseIncompleteLikelihood: High

Description

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-50

CVEs mapped to this weakness (309)

page 3 of 16
  • CVE-2021-36209CriAug 6, 2021
    risk 0.64cvss 9.8epss 0.01

    In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.

  • CVE-2021-22763CriJun 11, 2021
    risk 0.64cvss 9.8epss 0.02

    A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to…

  • CVE-2021-28293CriJun 8, 2021
    risk 0.64cvss 9.8epss 0.02

    Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generated via the password reset functionality, and thus an…

  • CVE-2021-22731CriMay 26, 2021
    risk 0.64cvss 9.8epss 0.01

    Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.

  • CVE-2020-27179CriOct 27, 2020
    risk 0.64cvss 9.8epss 0.01

    konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens.

  • CVE-2020-25105CriSep 3, 2020
    risk 0.64cvss 9.8epss 0.01

    eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).

  • CVE-2019-17392CriNov 26, 2019
    risk 0.64cvss 9.8epss 0.01

    Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.

  • CVE-2019-15929CriOct 24, 2019
    risk 0.64cvss 9.8epss 0.02

    In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.

  • CVE-2018-16988CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the…

  • CVE-2019-11393CriApr 22, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.

  • CVE-2018-16529CriMar 28, 2019
    risk 0.64cvss 9.8epss 0.02

    A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password.

  • CVE-2018-19488CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.04

    The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote unauthenticated attackers to reset the password of a user's account.

  • CVE-2018-18871CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.02

    Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password).

  • CVE-2018-7811CriNov 30, 2018
    risk 0.64cvss 9.8epss 0.04

    An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web server

  • CVE-2018-7809CriNov 30, 2018
    risk 0.64cvss 9.8epss 0.02

    An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the password delete function of the web server.

  • CVE-2018-17881CriOct 3, 2018
    risk 0.64cvss 9.8epss 0.01

    On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin password change.

  • CVE-2018-17298CriSep 21, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password.

  • CVE-2018-1000554CriJun 26, 2018
    risk 0.64cvss 9.8epss 0.01

    Trovebox version <= 4.0.0-rc6 contains a Unsafe password reset token generation vulnerability in user component that can result in Password reset. This attack appear to be exploitable via HTTP request. This vulnerability appears to have been fixed in after commit 742b8ed.

  • CVE-2018-12421CriJun 14, 2018
    risk 0.64cvss 9.8epss 0.03

    LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.

  • CVE-2018-10081CriApr 13, 2018
    risk 0.64cvss 9.8epss 0.02

    CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared, as demonstrated by a hash beginning with the "0e" substring.