CVE-2025-0674 – Elber Password Management Authentication Bypass

The following table lists the changes that have been made to the
CVE-2025-0674 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 07, 2025

    Action Type Old Value New Value
    Added Description Multiple Elber products are affected by an authentication bypass
    vulnerability which allows unauthorized access to the password
    management functionality. Attackers can exploit this issue by
    manipulating the endpoint to overwrite any user’s password within the
    system. This grants them unauthorized administrative access to protected
    areas of the application, compromising the device’s system security.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-288
    Added Reference https://www.cisa.gov/news-events/ics-advisories/icsa-25-035-03
Share the Post:

Related Posts