CyberRota Analysis
AI-GeneratedThe Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 is vulnerable due to inadequate server-side authorization on the administrative password-change function, allowing authenticated users to change the installer account password. This flaw poses a significant risk, as it could enable unauthorized access to administrative controls, potentially compromising the entire system. Organizations utilizing this firmware should prioritize remediation to mitigate the risk of unauthorized administrative access.
Original NVD Description
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.