vendor:
BEWARD Intercom
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Credentials Disclosure
798
CWE
Product Name: BEWARD Intercom
Affected Version From: 2.2.7.4
Affected Version To: 2.3.1.34471
Patch Exists: NO
Related CWE:
CPE: a:beward_r&d:beward_intercom:2.3.1
Platforms Tested: Microsoft Windows 10 Home, Microsoft Windows 7 SP1
2019
BEWARD Intercom 2.3.1 Credentials Disclosure
The application stores logs and sensitive information in an unencrypted binary file called BEWARD.INTERCOM.FDB. A local attacker that has access to the current user session can successfully disclose plain-text credentials that can be used to bypass authentication to the affected IP camera and door station and bypass access control in place.
Mitigation:
Encrypt or protect sensitive information stored in the BEWARD.INTERCOM.FDB file. Implement strong authentication mechanisms to prevent unauthorized access.