Vulnerabilities > CVE-2009-0656 - Credentials Management vulnerability in Asus Smartlogon 1.0.0005
Attack vector
LOCAL Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Asus SmartLogon 1.0.0005 allows physically proximate attackers to bypass "security functions" by presenting an image with a modified viewpoint that matches the posture of a stored image of the authorized notebook user.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
References
- http://security.bkis.vn/?p=292
- http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Nguyen
- http://www.blackhat.com/presentations/bh-dc-09/Nguyen/BlackHat-DC-09-Nguyen-Face-not-your-password.pdf
- http://www.securityfocus.com/archive/1/498997
- http://www.securityfocus.com/bid/32700
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48962