VulnerabilityModified
CVE-2019-12390
Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this information without credentials via port tcp/5010.
MEDIUM 5.3EPSS 1.40%
Does this matter?
Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.
Description
Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this information without credentials via port tcp/5010.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- anviz/anviz firmware
- Source
- cve@mitre.org
References
- https://www.0x90.zone/multiple/reverse/2019/11/28/Anviz-pwn.htmlThird Party Advisory
- https://www.0x90.zone/multiple/reverse/2019/11/28/Anviz-pwn.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.