The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.
Credits
Francesco La Spina and Stanislav Dashevskyi of Forescout Technologies reported the vulnerability for the EDS3000PS series to CISA.