The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.
History

Fri, 05 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Maxhub
Maxhub pivot
Vendors & Products Maxhub
Maxhub pivot

Thu, 04 Dec 2025 22:00:00 +0000

Type Values Removed Values Added
Description The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.
Title MAXHUB Pivot Weak Password Recovery Mechanism for Forgotten Password
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-12-04T21:44:06.466Z

Updated: 2025-12-05T19:21:16.638Z

Reserved: 2025-07-30T19:03:10.106Z

Link: CVE-2025-53704

cve-icon Vulnrichment

Updated: 2025-12-05T19:21:11.788Z

cve-icon NVD

Status : Received

Published: 2025-12-04T22:15:48.743

Modified: 2025-12-04T22:15:48.743

Link: CVE-2025-53704

cve-icon Redhat

No data.