CVE Vulnerabilities

CVE-2009-0655

Improper Authentication

Published: Feb 20, 2009 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a plain image of the authorized user.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Veriface Lenovo iii (including) iii (including)

Potential Mitigations

References