VYPR

access control devices

by Anviz

CVEs (6)

  • CVE-2019-12394CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.

  • CVE-2019-12392CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Anviz access control devices allow remote attackers to issue commands without a password.

  • CVE-2019-12393HigDec 2, 2019
    risk 0.49cvss 7.5epss 0.01

    Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests.

  • CVE-2019-12389HigDec 2, 2019
    risk 0.49cvss 7.5epss 0.02

    Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via port tcp/5010.

  • CVE-2019-12388HigDec 2, 2019
    risk 0.49cvss 7.5epss 0.01

    Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/5010.

  • CVE-2019-12390MedDec 2, 2019
    risk 0.35cvss 5.3epss 0.01

    Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this information without credentials via port tcp/5010.