Description
Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.
Problem types
CWE-20 Improper Input Validation
Product status
2.9.11.6
Credits
Jakob Hagl (SBA Research)
Marija Radosavljević (SBA Research)
Fabian Funder (SBA Research)
References
github.com/...-02_Suprema_BioStar_2_Insecure_Password_Change
www.supremainc.com/...hybrid-security-platform-biostar-2.asp