ZeroHour

CVE-2019-25241

PoC ×2
CVSS 3.1
9.8 critical
EPSS
<1%p53
Published
()
Modified
Description

FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.

Vendors
iwt
Products
facesentry access control system firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.