CVE-2019-12389 is a critical vulnerability affecting Anviz access control devices, allowing remote attackers to extract sensitive user credentials (names and passwords) without authentication. This flaw, rated High (CVSS 7.5), stems from the devices exposing this information via TCP port 5010, requiring no user interaction or privileges for exploitation. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the direct exposure of credentials poses a significant risk to affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:anviz:anviz_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.