Security Advisory

CVE-2024-7265

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-08-07 10:58:25
Last updated 2025-03-17 08:34:48
Assigner CERT-PL
State PUBLISHED

Description

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, including root user, which could lead to privilege escalation. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.