Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to change passwords of all other users including administrators leading to a privilege escalation.
History

Mon, 03 Mar 2025 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862

Mon, 03 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Description Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to change passwords of all other users including administrators leading to a privilege escalation. Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to change passwords of all other users including administrators leading to a privilege escalation.
Title Improper authorisation in Uptime DC Improper authorisation in Uptime DC

Thu, 19 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2023-10-04T10:54:27.047Z

Updated: 2025-03-03T17:06:01.848Z

Reserved: 2023-09-15T12:45:58.751Z

Link: CVE-2023-4997

cve-icon Vulnrichment

Updated: 2024-08-02T07:44:53.695Z

cve-icon NVD

Status : Modified

Published: 2023-10-04T11:15:10.563

Modified: 2025-03-03T17:15:11.153

Link: CVE-2023-4997

cve-icon Redhat

No data.