← back
CVE-2022-26872highCWE-640

Password reset interception via API

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.3epss 0.8%
exploitation probability
0.8%top 48% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in AMI Megarac's API allows attackers to intercept password reset requests, potentially gaining unauthorized access to accounts. This happens because the API doesn't properly secure the password reset process, making it vulnerable to interception attacks.

Technical detail

The API endpoint handling password reset operations in AMI Megarac fails to implement adequate protection against request interception, allowing an attacker to capture or manipulate password reset tokens or credentials in transit. This vulnerability requires network-level access or a man-in-the-middle position to exploit, and successful exploitation results in account takeover.

Summary generated and translated by AI from the official description.
AMI Megarac Password reset interception via API
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H