SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-12390

Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this information without credentials via port tcp/5010.

MEDIUM 5.3EPSS 1.40%

Does this matter?

Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.

Description

Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this information without credentials via port tcp/5010.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.40% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
anviz/anviz firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.