Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Recovery Exploitation, Bypassing Physical Security.This issue affects ACS100, ACS300: from 5.2.4 before 6.2.4.3.
References
Link | Resource |
---|---|
https://sra.io/advisories/ | Third Party Advisory |
https://sra.io/advisories/ | Third Party Advisory |
https://support.brivo.com/l/en/article/g82txdwepa-brivo-firmware-release-notes#brivo_firmware_release_6_2_4_3 | Release Notes |
https://support.brivo.com/l/en/article/g82txdwepa-brivo-firmware-release-notes#brivo_firmware_release_6_2_4_3 | Release Notes |
Configurations
History
01 Apr 2025, 15:36
Type | Values Removed | Values Added |
---|---|---|
First Time |
Brivo acs100
Brivo acs300 Firmware Brivo acs100 Firmware Brivo Brivo acs300 |
|
CWE | CWE-522 | |
References | () https://support.brivo.com/l/en/article/g82txdwepa-brivo-firmware-release-notes#brivo_firmware_release_6_2_4_3 - Release Notes | |
References | () https://sra.io/advisories/ - Third Party Advisory | |
CPE | cpe:2.3:h:brivo:acs300:*:*:*:*:*:*:*:* cpe:2.3:o:brivo:acs100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:brivo:acs300_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:brivo:acs100:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.6 |
21 Feb 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
19 Feb 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-19 22:15
Updated : 2025-04-01 15:36
NVD link : CVE-2023-6259
Mitre link : CVE-2023-6259
JSON object : View
Products Affected
brivo
- acs300_firmware
- acs300
- acs100_firmware
- acs100
CWE
CWE-522
Insufficiently Protected Credentials