SB2019070202 - Authentication bypass in iDoors Reader



SB2019070202 - Authentication bypass in iDoors Reader

Published: July 2, 2019

Security Bulletin ID SB2019070202
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Authentication bypass using an alternate path or channel (CVE-ID: CVE-2019-5964)

The vulnerability allows an attacker to operate the product.

The vulnerability exist due to improper implementation of the authentication process. An attacker on the local network can bypass authentication process and gain unrestricted access to  management console.

Successful exploitation of the vulnerability may allow an attacker to change the device settings, reset the administrator account, and use the management screen.

Remediation

Install update from vendor's website.