Description
FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication credentials. Attackers can perform man-in-the-middle attacks to capture HTTP cookie authentication information during network communication.
Problem types
Cleartext Transmission of Sensitive Information
Product status
5.7.2 build 568
5.7.0 build 539
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5528.php (Zero Science Lab Vulnerability Advisory)
packetstormsecurity.com/files/153498 (Packet Storm Security Exploit Entry)
exchange.xforce.ibmcloud.com/vulnerabilities/163192 (IBM X-Force Vulnerability Exchange Entry)