First published: Thu Oct 27 2022(Updated: )
An access control issue in the password reset page of IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to arbitrarily change the admin password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ip-com EW9 Firmware | =15.11.0.14 | |
Ip-com EW9 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43364 is considered to have a high severity due to its potential to allow unauthorized password changes.
To fix CVE-2022-43364, update the IP-COM EW9 firmware to a version that has addressed the access control vulnerability.
CVE-2022-43364 affects the IP-COM EW9 firmware version 15.11.0.14.
Yes, CVE-2022-43364 can be exploited remotely by unauthenticated attackers.
The implications of CVE-2022-43364 include the potential for attackers to gain unauthorized access by changing the admin password.