8.3
CVE-2014-2938
- EPSS 0.56%
- Veröffentlicht 22.05.2014 20:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hanon ≫ Faceid F810 Firmware Version <= 1.007.109
Hanon ≫ Faceid F710 Firmware Version1.007.109
Hanon ≫ Faceid Fk800 Firmware Version <= 1.007.109
Hanon ≫ Faceid Fa007 Firmware Version <= 1.007.109
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.56% | 0.675 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.3 | 8.6 | 8.5 |
AV:N/AC:M/Au:N/C:P/I:C/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.