An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browse
An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive informatio
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password rese
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitt
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed thr
EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management fun
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authen
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their accou
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attack
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accep
blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authentica
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authentic
Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the applicati
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on O
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MO
Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the pr
A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file i
A low-privileged user can bypass account credentials without confirming the user's current authentication state, which m
Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. Th
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise
Frequently Asked Questions
What is CWE-620?
CWE-620 (CWE-620) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-620?
There are 26 CVE records associated with CWE-620 in our database. Of these, 6 are critical severity, 11 are high severity, and 3 are medium severity.
How can I protect against CWE-620 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-620 using AI-powered security agents.
Detect CWE-620 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-620 vulnerabilities across your infrastructure.
Get Started