Back

CRITICAL

Anviz Global M3 Outdoor RFID Access Control executes any command received from any source

Published Jun 6, 2019

Description

Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 6, 2019
Updated Aug 4, 2024
Reserved Apr 25, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mitre
Published Jun 6, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-3194