CVE-2014-2938

Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.
References
Link Resource
http://www.kb.cert.org/vuls/id/767044 Third Party Advisory US Government Resource
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hanon:faceid_f810_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanon:faceid:f810:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hanon:faceid_f710_firmware:1.007.109:*:*:*:*:*:*:*
cpe:2.3:h:hanon:faceid:f710:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hanon:faceid_fk800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanon:faceid:fk800:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hanon:faceid_fa007_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanon:faceid:fa007:*:*:*:*:*:*:*

Information

Published : 2014-05-22 13:55

Updated : 2014-07-16 11:54


NVD link : CVE-2014-2938

Mitre link : CVE-2014-2938


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

hanon

  • faceid_f710_firmware
  • faceid
  • faceid_fa007_firmware
  • faceid_fk800_firmware
  • faceid_f810_firmware