Advisories

COMMAX Biometric Access Control System Authentication Bypass

Go Back
severity
high
date
Affecting
  • COMMAX Biometric Access Control System 1.0.0

CWE
  • CWE-565 Reliance on Cookies without Validation and Integrity Checking
CVSS
8.7
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Credit
LiquidWorm as Gjoko Krstic of Zero Science Lab
Description
COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent physical controls in smart homes and buildings by exploiting cookie poisoning. Attackers can forge cookies to bypass authentication and disclose sensitive information.