CWE-640— Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.— MITRE CWE catalog
321 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 1 of 7
- CVE-2009-5025HIGHCVSS 7.5EG 7.52020-01-15
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.
- CVE-2012-5618CRITICALCVSS 9.8EG 9.82020-02-04
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
- CVE-2012-5686CRITICALCVSS 9.8EG 9.82020-02-04
ZPanel 10.0.1 has insufficient entropy for its password reset process.
- CVE-2014-6412HIGHCVSS 8.1EG 8.12018-04-12
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
- CVE-2015-10071HIGHCVSS 2.6EG 7.52023-01-19
A vulnerability was found in gitter-badger ezpublish-modern-legacy. It has been rated as problematic. This issue affects some unknown processing of the file kernel/user/forgotpassword.php. The manipulation leads to weak password recovery. …
- CVE-2015-3189LOWCVSS 3.7EG 3.72017-05-25
With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current emai…
- CVE-2015-4689CRITICALCVSS 9.8EG 9.82017-09-11
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset."
- CVE-2015-5172CRITICALCVSS 9.8EG 9.82017-10-24
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
- CVE-2015-7257HIGHCVSS 7.5EG 7.52017-08-24
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username par…
- CVE-2016-2349HIGHCVSS 7.5EG 7.52016-12-21
Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.
- CVE-2016-5996HIGHCVSS 7.5EG 7.52016-09-26
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.…
- CVE-2016-5997MEDIUMCVSS 6.5EG 6.52016-09-26
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.…
- CVE-2016-7038HIGHCVSS 7.3EG 7.32017-01-20
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
- CVE-2016-8716HIGHCVSS 7.5EG 7.52017-04-12
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits th…
- CVE-2017-0921HIGHCVSS 8.1EG 8.12018-07-03
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromi…
- CVE-2017-1000141MEDIUMCVSS 6.5EG 6.52018-01-30
An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, deleting account). The correct behavior…
- CVE-2017-12161HIGHCVSS 8.8EG 8.82018-02-21
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid re…
- CVE-2017-12850HIGHCVSS 8.8EG 8.82017-08-14
An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard before 1.0.46.
- CVE-2017-12851HIGHCVSS 8.8EG 8.82017-08-14
An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.
- CVE-2017-14005HIGHCVSS 8.8EG 8.82017-10-17
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is au…
- CVE-2017-17097CRITICALCVSS 9.8EG 9.82018-01-02
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which mak…
- CVE-2017-2614MEDIUMCVSS 6.8EG 6.82018-07-27
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accoun…
- CVE-2017-2766CRITICALCVSS 9.8EG 9.82017-02-03
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could po…
- CVE-2017-5594HIGHCVSS 7.5EG 7.52017-01-25
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. …
- CVE-2017-7551CRITICALCVSS 9.8EG 9.82017-08-16
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
- CVE-2017-7615CRITICALCVSS 8.8EG 9.02017-04-16
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
- CVE-2017-7629HIGHCVSS 7.5EG 7.52017-06-15
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
- CVE-2017-7731HIGHCVSS 7.5EG 7.52017-05-27
A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature.
- CVE-2017-8295MEDIUMCVSS 5.9EG 5.92017-05-04
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arran…
- CVE-2017-8385MEDIUMCVSS 5.3EG 5.32017-05-01
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
- CVE-2017-8613HIGHCVSS 8.1EG 8.12017-06-29
Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege V…
- CVE-2017-8916HIGHCVSS 7.8EG 7.82018-01-31
In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.
- CVE-2017-9543HIGHCVSS 7.5EG 7.52017-06-12
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST request to registresult.htm.
- CVE-2018-0696HIGHCVSS 7.5EG 7.52019-02-13
OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.
- CVE-2018-0787HIGHCVSS 8.8EG 8.82018-03-14
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".
- CVE-2018-1000501CRITICALCVSS 9.8EG 9.82018-06-26
Instant Update CMS contains a Password Reset Vulnerability vulnerability in /iu-application/controllers/administration/auth.php that can result in Account Tackover. This attack appear to be exploitable via network connectivity. This vulner…
- CVE-2018-1000554CRITICALCVSS 9.8EG 9.82018-06-26
Trovebox version <= 4.0.0-rc6 contains a Unsafe password reset token generation vulnerability in user component that can result in Password reset. This attack appear to be exploitable via HTTP request. This vulnerability appears to have be…
- CVE-2018-1000812HIGHCVSS 8.1EG 8.12018-12-20
Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password recovery process, line 45 of general/password_recovery.php that …
- CVE-2018-10081CRITICALCVSS 9.8EG 9.82018-04-13
CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared, as demonstrated by a hash beginning with the "0e" substring.
- CVE-2018-10210MEDIUMCVSS 5.3EG 5.32018-04-25
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the password-reset feature.
- CVE-2018-11134HIGHCVSS 8.8EG 8.82018-05-31
In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of the available comman…
- CVE-2018-12315MEDIUMCVSS 6.5EG 6.52018-12-04
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.
- CVE-2018-12421CRITICALCVSS 9.8EG 9.82018-06-14
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constr…
- CVE-2018-12579HIGHCVSS 8.1EG 8.12018-08-20
An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8,…
- CVE-2018-16529CRITICALCVSS 9.8EG 9.82019-03-28
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password.
- CVE-2018-16988CRITICALCVSS 9.8EG 9.82019-05-02
An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situat…
- CVE-2018-17298CRITICALCVSS 9.8EG 9.82018-09-21
An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password.
- CVE-2018-17401HIGHCVSS 8.8EG 8.82018-09-23
The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by exploiting its Forgot Password feature. NOTE: the vendor says that, to exploit this, the us…
- CVE-2018-17881CRITICALCVSS 9.8EG 9.82018-10-03
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin password change.
- CVE-2018-18871CRITICALCVSS 9.8EG 9.82018-12-20
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without…
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →