Iconics GENESIS32 and BizViz Local Authentication Bypass Vulnerability
BID:54732
Info
Iconics GENESIS32 and BizViz Local Authentication Bypass Vulnerability
| Bugtraq ID: | 54732 |
| Class: | Design Error |
| CVE: |
CVE-2012-3018 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 30 2012 12:00AM |
| Updated: | Mar 19 2015 08:11AM |
| Credit: | Dr. Wesley McGrew of Mississippi State University |
| Vulnerable: |
ICONICS, Inc. GENESIS32 9.22 ICONICS, Inc. BizViz 9.22 |
| Not Vulnerable: | |
Discussion
Iconics GENESIS32 and BizViz Local Authentication Bypass Vulnerability
Iconics GENESIS32 and BizViz are prone to a local authentication-bypass vulnerability.
A local attacker can exploit this issue to bypass authentication methods and gain unauthorized administrative access in the Security Configurator. Successful exploits may lead to other attacks.
Iconics GENESIS32 and BizViz versions 9.22 and prior are vulnerable.
Iconics GENESIS32 and BizViz are prone to a local authentication-bypass vulnerability.
A local attacker can exploit this issue to bypass authentication methods and gain unauthorized administrative access in the Security Configurator. Successful exploits may lead to other attacks.
Iconics GENESIS32 and BizViz versions 9.22 and prior are vulnerable.
Exploit / POC
Iconics GENESIS32 and BizViz Local Authentication Bypass Vulnerability
An attacker can carry out this attack by gaining physical access to a vulnerable computer.
An attacker can carry out this attack by gaining physical access to a vulnerable computer.
Solution / Fix
Iconics GENESIS32 and BizViz Local Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Iconics GENESIS32 and BizViz Local Authentication Bypass Vulnerability
References:
References:
- GENESIS32 Homepage (ICONICS Inc)
- Vendor Homepage (ICONICS, Inc.)