CVE-2014-2938

Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.
References
Link Resource
http://www.kb.cert.org/vuls/id/767044 Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/767044 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hanon:faceid_f810_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanon:faceid:f810:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hanon:faceid_f710_firmware:1.007.109:*:*:*:*:*:*:*
cpe:2.3:h:hanon:faceid:f710:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hanon:faceid_fk800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanon:faceid:fk800:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hanon:faceid_fa007_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanon:faceid:fa007:*:*:*:*:*:*:*

History

21 Nov 2024, 02:07

Type Values Removed Values Added
References () http://www.kb.cert.org/vuls/id/767044 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/767044 - Third Party Advisory, US Government Resource

Information

Published : 2014-05-22 20:55

Updated : 2024-11-21 02:07


NVD link : CVE-2014-2938

Mitre link : CVE-2014-2938

CVE.ORG link : CVE-2014-2938


JSON object : View

Products Affected

hanon

  • faceid_f810_firmware
  • faceid_fa007_firmware
  • faceid_f710_firmware
  • faceid
  • faceid_fk800_firmware
CWE
CWE-287

Improper Authentication