vendor:
Soyal Biometric Access Control System
by:
LiquidWorm
7.5
CVSS
HIGH
Master Code Disclosure
319
CWE
Product Name: Soyal Biometric Access Control System
Affected Version From: AR-727 i/CM - F/W: 5.0
Affected Version To: AR-837E - F/W: 3.03
Patch Exists: NO
Related CWE:
CPE: a:soyal:biometric_access_control_system:5.0
Platforms Tested: SOYAL Technology WebServer 2.0, SOYAL Serial Device Server 4.03A, SOYAL Serial Device Server 4.01n, SOYAL Serial Device Server 3.07n
2021
SOYAL Biometric Access Control System 5.0 – Master Code Disclosure
The controller suffers from a cleartext transmission of sensitive information. This allows interception of the HTTP traffic and disclose the Master code and the Arming code via a man-in-the-middle attack. An attacker can obtain these codes to enter into the controller's Programming mode and bypass physical security controls in place.
Mitigation:
To mitigate this vulnerability, it is recommended to update the firmware to a secure version that encrypts the transmission of sensitive information.