I am unable to replicate this issue by using WHM's password modification feature.
Things to check for:
1. Is the customer closing their web browser after logging out? If you are using the default HTTP authentication, the user is logged in until they close their web browser.
2. When logging in as the customer with their password, do you ever see a message at the top indicating they're logged in as a reseller?
If the user is closing their browser and they aren't logging in with their username and a reseller's password (which can happen if a reseller has a weak or commonly used password), please submit a support ticket so we can see his happening on your server and determine the cause of this issue:
http://tickets.cPanel.net/submit