Access Control Devices Expose Sensitive Information by Anviz
CVE-2019-12390
5.3MEDIUM
What is CVE-2019-12390?
Anviz access control devices are susceptible to security vulnerabilities that enable remote attackers to query private information, including pin codes and user names, without the need for authentication. This issue arises through an open TCP port (tcp/5010), allowing unauthorized access to data that should be protected, posing significant risks to user privacy and organizational security.
