FaceSentry Access Control System 6.4.8 Authentication Credential Disclosure
Posted by deepcore on July 2, 2019 – 3:12 pm
FaceSentry Access Control System version 6.4.8 suffers from a cleartext transmission of sensitive information. This allows a remote attacker to intercept the HTTP Cookie authentication credentials via a man-in-the-middle attack.
Post a reply
You must be logged in to post a comment.