Vulnerabilities > CVE-2009-0657 - Credentials Management vulnerability in Toshiba Face Recognition 2.0.2.32
Attack vector
LOCAL Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large number of images for which the viewpoint and lighting have been modified to match a stored image of the authorized notebook user.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Hardware | 1 |
Common Weakness Enumeration (CWE)
References
- http://security.bkis.vn/?p=292
- http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Nguyen
- http://www.blackhat.com/presentations/bh-dc-09/Nguyen/BlackHat-DC-09-Nguyen-Face-not-your-password.pdf
- http://www.securityfocus.com/archive/1/498997
- http://www.securityfocus.com/bid/32700
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48963