Suprema BioStar 2
cpe:2.3:a:supremainc:biostar_2:*:*:*:*:*:*:*
- 2.9.11.6
A vulnerability in Suprema's BioStar 2 access control management system, specifically in version 2.9.11.6, allows users to change their password without entering the current one. This client-side flaw can be exploited, particularly in conjunction with other vulnerabilities, to gain unauthorized access to user accounts and potentially compromise the system.
Exploitation of this vulnerability could lead to unauthorized account access, allowing an attacker to take over a user's account permanently.
To reproduce this vulnerability, send a request to the BioStar 2 API users endpoint, including a new password in the request body but omitting the current password. The server will accept the request and change the password successfully. After the password is changed, it can be used to log in to the account, indicating that the password change was successful.
Contact Suprema for the patch available in version 2.9.11.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.