6.9

CVE-2009-0655

Exploit
Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Veriface Version iii
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.313
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://security.bkis.vn/?p=292
Exploit
http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Nguyen
http://www.blackhat.com/presentations/bh-dc-09/Nguyen/BlackHat-DC-09-Nguyen-Face-not-your-password.pdf
Exploit
http://www.securityfocus.com/archive/1/498997
http://www.securityfocus.com/bid/32700
https://exchange.xforce.ibmcloud.com/vulnerabilities/48961