Overview
Hanvon facial recognition (Face ID) devices possibly running software versions prior to 1.007.110 could allow an unauthenticated attacker to modify user and access control information.
Description
CWE-306: Missing Authentication for Critical Function It has been reported that Hanvon biometric facial recognition devices running software versions prior to 1.007.110 do not authenticate network connections or API commands. Hanvon devices provide a plain-text management protocol/API on port 9922/tcp. An attacker with network access can connect to devices using telnet or a similar terminal or TCP socket utility, with no authentication. |
Impact
An unauthenticated attacker with network access to vulnerable devices on 9922/tcp could create, modify, and delete user and access control information. This could allow the attacker to bypass authentication and authorization for physical access or time and attendance tracking. |
Solution
Update |
Restrict Access |
Vendor Information (Learn More)
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
Hanvon Technology Co | Affected | - | 07 May 2014 |
If you are a vendor and your product is affected, let us know.
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | 8.3 | AV:N/AC:M/Au:N/C:P/I:C/A:P |
Temporal | 6.2 | E:POC/RL:OF/RC:UR |
Environmental | 2.0 | CDP:MH/TD:L/CR:ND/IR:H/AR:ND |
References
- http://www.hanvon.com/En/products/FaceID/technology/index.html
- http://www.hanvon.com/en/products/FaceID/products/index.html
- http://cwe.mitre.org/data/definitions/306.html
Credit
Thanks to Kelvin Tan Thiam Teck for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
- CVE IDs: CVE-2014-2938
- Date Public: 20 5월 2014
- Date First Published: 20 5월 2014
- Date Last Updated: 20 5월 2014
- Document Revision: 16
'취약점 정보1' 카테고리의 다른 글
About the security content of Safari 6.1.4 and Safari 7.0.4 (0) | 2014.05.22 |
---|---|
MS Internet Explorer 8 원격코드 실행 신규 취약점 주의 권고 (0) | 2014.05.22 |
Advanced Exploitation of Mozilla Firefox Use-After-Free Vulnerability (Pwn2Own 2014) (0) | 2014.05.21 |
2014-05-21 취약점 정리 (0) | 2014.05.21 |
CHROME 35 FIXES 23 SECURITY FLAWS (0) | 2014.05.21 |