search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Hanvon facial recognition (Face ID) devices do not authenticate commands

Vulnerability Note VU#767044

Original Release Date: 2014-05-20 | Last Revised: 2014-05-20

Overview

Hanvon facial recognition (Face ID) devices possibly running software versions prior to 1.007.110 could allow an unauthenticated attacker to modify user and access control information.

Description

CWE-306: Missing Authentication for Critical Function

It has been reported that Hanvon biometric facial recognition devices running software versions prior to 1.007.110 do not authenticate network connections or API commands. Hanvon devices provide a plain-text management protocol/API on port 9922/tcp. An attacker with network access can connect to devices using telnet or a similar terminal or TCP socket utility, with no authentication.

It has been reported the following devices are affected: F710, F810, FA007, FK800, and earlier series. It is possible that all Hanvon facial recognition devices could be affected.

Impact

An unauthenticated attacker with network access to vulnerable devices on 9922/tcp could create, modify, and delete user and access control information. This could allow the attacker to bypass authentication and authorization for physical access or time and attendance tracking.

Solution

Update

It has been reported that this vulnerability has been addressed in software version 1.007.110. Affected users are advised to contact their device provider, integrator, or Hanvon to obtain updated software.

Restrict Access

As a general good security practice, only allow connections from trusted hosts and networks. Consider running sensitive access control systems on a separate network.

Vendor Information

767044
 

Hanvon Technology Co Affected

Updated:  May 07, 2014

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base 8.3 AV:N/AC:M/Au:N/C:P/I:C/A:P
Temporal 6.2 E:POC/RL:OF/RC:UR
Environmental 2.0 CDP:MH/TD:L/CR:ND/IR:H/AR:ND

References

Acknowledgements

Thanks to Kelvin Tan Thiam Teck for reporting this vulnerability.

This document was written by Michael Orlando.

Other Information

CVE IDs: CVE-2014-2938
Date Public: 2014-05-20
Date First Published: 2014-05-20
Date Last Updated: 2014-05-20 15:10 UTC
Document Revision: 16

Sponsored by CISA.