CVE-2019-12394

EUVD-2019-4027
Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H