SB2021030106 - Privilege escalation in ProSoft Technology ICX35



SB2021030106 - Privilege escalation in ProSoft Technology ICX35

Published: March 1, 2021

Security Bulletin ID SB2021030106
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-22661)

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to changing the password on the module webpage does not require the user to type in the current password first. A remote attacker can change the current user’s password and alter device configurations.


Remediation

Install update from vendor's website.