oM noM Security Feeds cve
vulnerability context

CVE-2017-20235

CVSS 9.1 CRITICALEPSS 25%CWE-287

ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the authentication mechanism in affected firmware versions to obtain full administrative access to device configuration and settings.

Published 2026-04-03 · last modified 2026-04-22

details

CISA KEV status
Not in catalog
CVSS v3
9.1 / CRITICAL
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
25% percentile (score 0.0009)
CWE
CWE-287

source mentions 1

source consensus

  • Bluesky:@cyberhub.blog
Want the 3-bullet summary of CVE-2017-20235, plus webhook alerts when KEV is updated? Pro is $10/mo.