CVE-2019-25436: Sricam DeviceViewer 3.12.0.1 Password Change Security Bypass
Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old password field. Attackers can inject a large payload into the old password parameter during the change password process to bypass validation and set an arbitrary new password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25436?
CVE-2019-25436 is classified as a high severity vulnerability due to its potential for exploitation by authenticated users.
How do I fix CVE-2019-25436?
To fix CVE-2019-25436, update Sricam DeviceViewer to the latest version which addresses the password change security bypass.
Who is affected by CVE-2019-25436?
CVE-2019-25436 affects users of Sricam DeviceViewer version 3.12.0.1 and potentially earlier versions.
What impact does CVE-2019-25436 have on users?
CVE-2019-25436 allows authenticated users to change passwords without validating the old password, which compromises account security.
Is CVE-2019-25436 being actively exploited?
There have been reports suggesting that CVE-2019-25436 may be exploited in the wild, emphasizing the need for prompt remediation.