9.8

CVE-2018-1000554

Exploit
Trovebox version <= 4.0.0-rc6 contains a Unsafe password reset token generation vulnerability in user component that can result in Password reset. This attack appear to be exploitable via HTTP request. This vulnerability appears to have been fixed in after commit 742b8ed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trovebox ≫ Trovebox Version <= 3.0.0
Trovebox ≫ Trovebox Version 4.0.0 Update rc2
Trovebox ≫ Trovebox Version 4.0.0 Update rc5
Trovebox ≫ Trovebox Version 4.0.0 Update rc6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.21% 0.643
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-640 Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

https://telekomsecurity.github.io/2018/04/trovebox-vulnerabilities.html
Third Party Advisory
Exploit