logo

Technical Advisory – ICTFAX 7-4 – Indirect Object Reference

ID: c02bc274-7215-5553-8f0c-7c43076727fa

STIX ID: report--c02bc274-7215-5553-8f0c-7c43076727fa

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

ADMIRALTY:B6
...
...

This advisory describes an insecure direct object reference in ICTFax that allows an authenticated low-privilege user to reset any user's password (including administrators) by altering a numeric user identifier in the password-change request; the report includes reproduction steps, impact assessment, a recommendation to require current password re-entry, and a vendor disclosure timeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.