CVE-2014-2938

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
22/05/2014
Last modified:
12/04/2025

Description

Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hanon:faceid_f810_firmware:*:*:*:*:*:*:*:* 1.007.109 (including)
cpe:2.3:h:hanon:faceid:f810:*:*:*:*:*:*:*
cpe:2.3:o:hanon:faceid_f710_firmware:1.007.109:*:*:*:*:*:*:*
cpe:2.3:h:hanon:faceid:f710:*:*:*:*:*:*:*
cpe:2.3:o:hanon:faceid_fk800_firmware:*:*:*:*:*:*:*:* 1.007.109 (including)
cpe:2.3:h:hanon:faceid:fk800:*:*:*:*:*:*:*
cpe:2.3:o:hanon:faceid_fa007_firmware:*:*:*:*:*:*:*:* 1.007.109 (including)
cpe:2.3:h:hanon:faceid:fa007:*:*:*:*:*:*:*