Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-25279

Опубликовано: 08 янв. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in /faceGuard/database/FaceSentryWeb.sqlite without additional authentication.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.0:*:*:*:*:*:*:*
cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.2:*:*:*:*:*:*:*
cpe:2.3:o:iwt:facesentry_access_control_system_firmware:6.4.8:*:*:*:*:*:*:*
cpe:2.3:h:iwt:facesentry_access_control_system:-:*:*:*:*:*:*:*

EPSS

Процентиль: 13%
0.00042
Низкий

7.5 High

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 8.2
github
около 1 месяца назад

FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in /faceGuard/database/FaceSentryWeb.sqlite without additional authentication.

EPSS

Процентиль: 13%
0.00042
Низкий

7.5 High

CVSS3

Дефекты

CWE-312