SB2019070202 - Authentication bypass in iDoors Reader
Published: July 2, 2019
Security Bulletin ID
SB2019070202
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Adjecent network
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Authentication bypass using an alternate path or channel (CVE-ID: CVE-2019-5964)
The vulnerability allows an attacker to operate the product.
The vulnerability exist due to improper implementation of the authentication process. An attacker on the local network can bypass authentication process and gain unrestricted access to management console.
Successful exploitation of the vulnerability may allow an attacker to change the device settings, reset the administrator account, and use the management screen.
Remediation
Install update from vendor's website.