CVE-2019-25278 PUBLISHED

FaceSentry Access Control System 6.4.8 Authentication Credentials MiTM Disclosure

Assigner: VulnCheck
Reserved: 06.01.2026 Published: 07.01.2026 Updated: 08.01.2026

FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication credentials. Attackers can perform man-in-the-middle attacks to capture HTTP cookie authentication information during network communication.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.1

Product Status

Vendor iWT Ltd.
Product FaceSentry Access Control System
Versions
  • Version 6.4.8 build 264 is affected
  • Version 5.7.2 build 568 is affected
  • Version 5.7.0 build 539 is affected

Credits

  • LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

Problem Types

  • Cleartext Transmission of Sensitive Information CWE