Access Control Devices Expose Sensitive Information by Anviz
CVE-2019-12390

5.3MEDIUM

Key Information:

Vendor

Anviz

Vendor
CVE Published:
2 December 2019

What is CVE-2019-12390?

Anviz access control devices are susceptible to security vulnerabilities that enable remote attackers to query private information, including pin codes and user names, without the need for authentication. This issue arises through an open TCP port (tcp/5010), allowing unauthorized access to data that should be protected, posing significant risks to user privacy and organizational security.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.