Permissions, Privileges, and Access Controls in ICX35-HWC-A and ICX35-HWC-E - CVE-2021-22661
Published: March 1, 2021
Vulnerability identifier: #VU51001
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22661
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to changing the password on the module webpage does not require the user to type in the current password first. A remote attacker can change the current user’s password and alter device configurations.
Affected software
ICX35-HWC-A
ICX35-HWC-E
ICX35-HWC-E
How to mitigate CVE-2021-22661
Install updates from vendor's website.
ICX35-HWC-A - update to 1.10.30
ICX35-HWC-E - update to 1.10.30
ICX35-HWC-E - update to 1.10.30