IWT FaceSentry Access Control System
cpe:2.3:h:iwt:facesentry_access_control_system:*:*:*:*:*:*:*, +1 more
- 6.4.8 build 264
- 5.7.2 build 568
- 5.7.0 build 539
This vulnerability is being actively exploited in the wild.
A critical authentication vulnerability has been identified in FaceSentry Access Control System version 6.4.8. The vulnerability arises from hard-coded SSH credentials for the wwwuser account, allowing unauthorized access. Attackers can exploit an insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.
Exploitation of this vulnerability allows for unauthorized SSH access as the wwwuser account, with subsequent privilege escalation to root.
The vulnerability can be reproduced by connecting to the device via SSH on port 23445 using the hard-coded credentials wwwuser and 123456. Once logged in, the wwwuser account can execute sudo commands without authentication, taking advantage of the insecure sudoers configuration to gain root access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.