Vulnerability Note VU#757840
Dovestones Software AD Self Password Reset fails to properly restrict password reset request to authorized users
Original Release date: 18 Dec 2015 | Last revised: 18 Dec 2015

Overview
Dovestones Software AD Self Password Reset, version 3.0.3.0 and earlier, fails to properly validate users, which enables an unauthenticated attacker to reset passwords for arbitrary accounts.

Description
CWE-284: Improper Access Control – CVE-2015-8267
Dovestones Software AD Self Password Reset contains a vulnerable method PasswordReset.Controllers.ResetController.ChangePasswordIndex() in PasswordReset.dll that fails to validate the requesting user. An attacker can reset passwords for arbitrary accounts by manipulating web application requests that call the vulnerable method.

Impact
A remote, unauthenticated attacker can reset passwords for arbitrary accounts where usernames are known or can be guessed.

Solution
Apply an update

The vendor has released version 3.0.4.0 and has worked directly with customers to address this and other vulnerabilities. Users are encouraged to update to the latest version.

Vendor Information (Learn More)

VendorStatusDate NotifiedDate UpdatedDovestones SoftwareAffected19 Oct 201518 Dec 2015If you are a vendor and your product is affected, let
us know.

CVSS Metrics (Learn More)

Group
Score
Vector

Base
7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal
5.9
E:POC/RL:OF/RC:C

Environmental
1.5
CDP:ND/TD:L/CR:ND/IR:ND/AR:ND

References

Security vulnerability in AD Self Password Reset versions older than 3.0.3.0

Active Directory Self-Service Password Reset


https://cwe.mitre.org/data/definitions/284.html

Credit

Thanks to Adam Caudill for reporting this vulnerability.
This document was written by Joel Land.

Other Information

CVE IDs:
CVE-2015-8267

Date Public:
18 Dec 2015

Date First Published:
18 Dec 2015

Date Last Updated:
18 Dec 2015

Document Revision:
10

FeedbackIf you have feedback, comments, or additional information about this vulnerability, please send us email.

Leave a Reply