CyberRota Analysis
AI-GeneratedA weak password recovery mechanism in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux, and Kubernetes allows remote, unauthorized attackers to take over user accounts. This vulnerability poses a significant risk to user data integrity and system security. ArcGIS Administrators should prioritize implementing a secure email server configuration to enhance the password recovery process and mitigate potential account takeover risks.
Original NVD Description
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.
Related CVEs
Other vulnerabilities affecting the same vendor(s)