FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication credentials. Attackers can perform man-in-the-middle attacks to capture HTTP cookie authentication information during network communication.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Facesentry_access_control_system_firmware | Iwt | 5.7.0 (including) | 5.7.0 (including) |
| Facesentry_access_control_system_firmware | Iwt | 5.7.2 (including) | 5.7.2 (including) |
| Facesentry_access_control_system_firmware | Iwt | 6.4.8 (including) | 6.4.8 (including) |