
Cloud Vulnerability DB
A community-led vulnerabilities database
An authentication bypass vulnerability was identified in the Password Reset component of Gladinet CentreStack versions before 13.5.9808 (CVE-2023-26829). The vulnerability was disclosed on March 31, 2023, and affects the authentication mechanism of the CentreStack platform (NVD).
The vulnerability allows remote attackers to bypass authentication controls in the Password Reset component. The severity of this vulnerability is rated as CRITICAL with a CVSS v3.1 Base Score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The vulnerability is classified under CWE-863 (Incorrect Authorization) (NVD).
The vulnerability enables remote attackers to set a new password for any valid user account without requiring knowledge of the previous password. This effectively results in a complete authentication bypass, potentially allowing unauthorized access to any user account in the system (NVD).
Users should upgrade to CentreStack version 13.5.9808 or later to address this vulnerability. The fix has been implemented in this version to prevent unauthorized password resets (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."