Refine your search
2 vulnerabilities found for iDoors Reader by A.T.WORKS, Inc.
CVE-2019-5964 (GCVE-0-2019-5964)
Vulnerability from cvelistv5
Published
2019-07-05 13:20
Modified
2024-08-04 20:09
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Authentication bypass
Summary
iDoors Reader 2.10.17 and earlier allows an attacker on the same network segment to bypass authentication to access the management console and operate the product via unspecified vectors.
References
| URL | Tags | |||||||
|---|---|---|---|---|---|---|---|---|
|
||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| A.T.WORKS, Inc. | iDoors Reader |
Version: 2.10.17 and earlier |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-04T20:09:23.938Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://idoors.jp/info/20190701"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN28218613/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "iDoors Reader",
"vendor": "A.T.WORKS, Inc.",
"versions": [
{
"status": "affected",
"version": "2.10.17 and earlier"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "iDoors Reader 2.10.17 and earlier allows an attacker on the same network segment to bypass authentication to access the management console and operate the product via unspecified vectors."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Authentication bypass",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2019-07-05T13:20:17.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://idoors.jp/info/20190701"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://jvn.jp/en/jp/JVN28218613/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2019-5964",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "iDoors Reader",
"version": {
"version_data": [
{
"version_value": "2.10.17 and earlier"
}
]
}
}
]
},
"vendor_name": "A.T.WORKS, Inc."
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "iDoors Reader 2.10.17 and earlier allows an attacker on the same network segment to bypass authentication to access the management console and operate the product via unspecified vectors."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Authentication bypass"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://idoors.jp/info/20190701",
"refsource": "MISC",
"url": "https://idoors.jp/info/20190701"
},
{
"name": "https://jvn.jp/en/jp/JVN28218613/index.html",
"refsource": "MISC",
"url": "https://jvn.jp/en/jp/JVN28218613/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2019-5964",
"datePublished": "2019-07-05T13:20:17.000Z",
"dateReserved": "2019-01-10T00:00:00.000Z",
"dateUpdated": "2024-08-04T20:09:23.938Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
jvndb-2019-000044
Vulnerability from jvndb
Published
2019-07-01 14:31
Modified
2019-10-04 15:45
Severity ?
Summary
The management console of iDoors Reader vulnerable to authentication bypass
Details
The management console of iDoors Reader provided by A.T.WORKS, Inc. contains an authentication bypass vulnerability (CWE-288).
Yusuke Nakano of Secure Cycle Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2019/JVNDB-2019-000044.html",
"dc:date": "2019-10-04T15:45+09:00",
"dcterms:issued": "2019-07-01T14:31+09:00",
"dcterms:modified": "2019-10-04T15:45+09:00",
"description": "The management console of iDoors Reader provided by A.T.WORKS, Inc. contains an authentication bypass vulnerability (CWE-288).\r\n\r\nYusuke Nakano of Secure Cycle Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2019/JVNDB-2019-000044.html",
"sec:cpe": {
"#text": "cpe:/a:idoors:idoors_reader",
"@product": "iDoors Reader",
"@vendor": "A.T.WORKS, Inc.",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "5.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:A/AC:L/Au:N/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2019-000044",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN28218613/index.html",
"@id": "JVN#28218613",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5964",
"@id": "CVE-2019-5964",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2019-5964",
"@id": "CVE-2019-5964",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-264",
"@title": "Permissions(CWE-264)"
}
],
"title": "The management console of iDoors Reader vulnerable to authentication bypass"
}