Vulnerabilities > Anviz > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-12-02 | CVE-2019-12393 | Authentication Bypass by Capture-replay vulnerability in Anviz Management System Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests. | 7.5 |
2019-12-02 | CVE-2019-12391 | Unspecified vulnerability in Anviz Management System The Anviz Management System for access control has insufficient logging for device events such as door open requests. | 7.5 |
2019-12-02 | CVE-2019-12389 | Missing Authentication for Critical Function vulnerability in Anviz Firmware Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via port tcp/5010. | 7.5 |
2019-12-02 | CVE-2019-12388 | Cleartext Transmission of Sensitive Information vulnerability in Anviz Firmware Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/5010. | 7.5 |