Vulnerabilities > Anviz > Management System

DATE CVE VULNERABILITY TITLE RISK
2019-12-02 CVE-2019-12394 Improper Authentication vulnerability in Anviz Management System
Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.
network
low complexity
anviz CWE-287
critical
9.8
2019-12-02 CVE-2019-12393 Authentication Bypass by Capture-replay vulnerability in Anviz Management System
Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests.
network
low complexity
anviz CWE-294
7.5
2019-12-02 CVE-2019-12391 Unspecified vulnerability in Anviz Management System
The Anviz Management System for access control has insufficient logging for device events such as door open requests.
network
low complexity
anviz
7.5