Severity

9.8

Vulnerability Type

Password Recovery Mechanism for Forgotten Password (CWE-640)

Summary

An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.