The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.
Metrics
Affected Vendors & Products
References
History
Mon, 12 May 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 12 May 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system. | |
Title | WormHole Tech GPM - Unverified Password Change | |
Weaknesses | CWE-620 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: twcert
Published: 2025-05-12T03:08:50.733Z
Updated: 2025-05-12T17:40:03.588Z
Reserved: 2025-05-12T01:49:30.350Z
Link: CVE-2025-4558

Updated: 2025-05-12T17:38:31.170Z

Status : Awaiting Analysis
Published: 2025-05-12T04:15:35.160
Modified: 2025-05-12T17:32:32.760
Link: CVE-2025-4558

No data.