ID

VAR-200902-0647


CVE

CVE-2009-0655


TITLE

Lenovo Veriface III In Windows Vulnerabilities to be logged into your account

Trust: 0.8

sources: JVNDB: JVNDB-2009-001436

DESCRIPTION

Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user. Face-recognition applications for multiple laptops are prone to an authentication-bypass vulnerability. An attacker can exploit this issue to gain unauthorized access to the affected device. This issue affects the following applications: Lenovo Veriface III Asus SmartLogon 1.0.0005 Toshiba Face Recognition 2.0.2.32. Lenovo Veriface III is a face recognition authentication system. Lenovo Veriface III has a permission bypass vulnerability

Trust: 1.98

sources: NVD: CVE-2009-0655 // JVNDB: JVNDB-2009-001436 // BID: 32700 // VULHUB: VHN-38101

AFFECTED PRODUCTS

vendor:lenovomodel:verifacescope:eqversion:iii

Trust: 2.4

vendor:toshibamodel:face recognitionscope:eqversion:2.0.2.32

Trust: 0.3

vendor:lenovomodel:veriface iiiscope: - version: -

Trust: 0.3

vendor:asusmodel:smartlogonscope:eqversion:1.0.6

Trust: 0.3

sources: BID: 32700 // JVNDB: JVNDB-2009-001436 // CNNVD: CNNVD-200902-477 // NVD: CVE-2009-0655

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-0655
value: MEDIUM

Trust: 1.0

NVD: CVE-2009-0655
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200902-477
value: MEDIUM

Trust: 0.6

VULHUB: VHN-38101
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2009-0655
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-38101
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-38101 // JVNDB: JVNDB-2009-001436 // CNNVD: CNNVD-200902-477 // NVD: CVE-2009-0655

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

problemtype:CWE-255

Trust: 0.8

sources: VULHUB: VHN-38101 // JVNDB: JVNDB-2009-001436 // NVD: CVE-2009-0655

THREAT TYPE

local

Trust: 0.9

sources: BID: 32700 // CNNVD: CNNVD-200902-477

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-200902-477

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-001436

PATCH

title:Top Pageurl:http://www.lenovo.com/jp/ja/

Trust: 0.8

sources: JVNDB: JVNDB-2009-001436

EXTERNAL IDS

db:NVDid:CVE-2009-0655

Trust: 2.8

db:BIDid:32700

Trust: 2.0

db:JVNDBid:JVNDB-2009-001436

Trust: 0.8

db:CNNVDid:CNNVD-200902-477

Trust: 0.7

db:BUGTRAQid:20081208 [SVRT-07-08] VULNERABILITY IN FACE RECOGNITION AUTHENTICATION MECHANISM OF LENOVO-ASUS-TOSHIBA LAPTOPS

Trust: 0.6

db:XFid:48961

Trust: 0.6

db:VULHUBid:VHN-38101

Trust: 0.1

sources: VULHUB: VHN-38101 // BID: 32700 // JVNDB: JVNDB-2009-001436 // CNNVD: CNNVD-200902-477 // NVD: CVE-2009-0655

REFERENCES

url:http://www.securityfocus.com/bid/32700

Trust: 1.7

url:http://www.securityfocus.com/archive/1/498997

Trust: 1.7

url:http://security.bkis.vn/?p=292

Trust: 1.7

url:http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#nguyen

Trust: 1.7

url:http://www.blackhat.com/presentations/bh-dc-09/nguyen/blackhat-dc-09-nguyen-face-not-your-password.pdf

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/48961

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-0655

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-0655

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/48961

Trust: 0.6

url:http://www.lenovo.com/ca/en/

Trust: 0.3

url:http://www.toshiba.com/

Trust: 0.3

url:/archive/1/498997

Trust: 0.3

url:http://www.asus.com/

Trust: 0.3

sources: VULHUB: VHN-38101 // BID: 32700 // JVNDB: JVNDB-2009-001436 // CNNVD: CNNVD-200902-477 // NVD: CVE-2009-0655

CREDITS

Nhat Minh, Nguyen Minh Duc, Bui Quang Minh and Le Minh Hung

Trust: 0.9

sources: BID: 32700 // CNNVD: CNNVD-200902-477

SOURCES

db:VULHUBid:VHN-38101
db:BIDid:32700
db:JVNDBid:JVNDB-2009-001436
db:CNNVDid:CNNVD-200902-477
db:NVDid:CVE-2009-0655

LAST UPDATE DATE

2025-04-10T23:15:38.647000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-38101date:2017-08-17T00:00:00
db:BIDid:32700date:2009-03-05T21:26:00
db:JVNDBid:JVNDB-2009-001436date:2009-06-30T00:00:00
db:CNNVDid:CNNVD-200902-477date:2009-06-09T00:00:00
db:NVDid:CVE-2009-0655date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-38101date:2009-02-20T00:00:00
db:BIDid:32700date:2008-12-08T00:00:00
db:JVNDBid:JVNDB-2009-001436date:2009-06-30T00:00:00
db:CNNVDid:CNNVD-200902-477date:2009-02-20T00:00:00
db:NVDid:CVE-2009-0655date:2009-02-20T19:30:00.327