SB2021030106 - Privilege escalation in ProSoft Technology ICX35
Published: March 1, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-22661)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to changing the password on the module webpage does not require the user to type in the current password first. A remote attacker can change the current user’s password and alter device configurations.
Remediation
Install update from vendor's website.