ID

VAR-200902-0648


CVE

CVE-2009-0656


TITLE

Asus SmartLogon In " Security function " Vulnerability to avoid

Trust: 0.8

sources: JVNDB: JVNDB-2009-003257

DESCRIPTION

Asus SmartLogon 1.0.0005 allows physically proximate attackers to bypass "security functions" by presenting an image with a modified viewpoint that matches the posture of a stored image of the authorized notebook user. Face-recognition applications for multiple laptops are prone to an authentication-bypass vulnerability. An attacker can exploit this issue to gain unauthorized access to the affected device. This issue affects the following applications: Lenovo Veriface III Asus SmartLogon 1.0.0005 Toshiba Face Recognition 2.0.2.32

Trust: 1.98

sources: NVD: CVE-2009-0656 // JVNDB: JVNDB-2009-003257 // BID: 32700 // VULHUB: VHN-38102

AFFECTED PRODUCTS

vendor:asusmodel:smartlogonscope:eqversion:1.0.0005

Trust: 1.6

vendor:asustek computermodel:smartlogonscope:eqversion:1.0.0005

Trust: 0.8

vendor:toshibamodel:face recognitionscope:eqversion:2.0.2.32

Trust: 0.3

vendor:lenovomodel:veriface iiiscope: - version: -

Trust: 0.3

vendor:asusmodel:smartlogonscope:eqversion:1.0.6

Trust: 0.3

sources: BID: 32700 // JVNDB: JVNDB-2009-003257 // CNNVD: CNNVD-200902-478 // NVD: CVE-2009-0656

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-0656
value: MEDIUM

Trust: 1.0

NVD: CVE-2009-0656
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200902-478
value: MEDIUM

Trust: 0.6

VULHUB: VHN-38102
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2009-0656
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-38102
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-38102 // JVNDB: JVNDB-2009-003257 // CNNVD: CNNVD-200902-478 // NVD: CVE-2009-0656

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.9

sources: VULHUB: VHN-38102 // JVNDB: JVNDB-2009-003257 // NVD: CVE-2009-0656

THREAT TYPE

local

Trust: 0.9

sources: BID: 32700 // CNNVD: CNNVD-200902-478

TYPE

trust management

Trust: 0.6

sources: CNNVD: CNNVD-200902-478

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-003257

PATCH

title:Top Pageurl:http://www.asus.com/

Trust: 0.8

sources: JVNDB: JVNDB-2009-003257

EXTERNAL IDS

db:NVDid:CVE-2009-0656

Trust: 2.8

db:BIDid:32700

Trust: 2.0

db:JVNDBid:JVNDB-2009-003257

Trust: 0.8

db:CNNVDid:CNNVD-200902-478

Trust: 0.7

db:XFid:48962

Trust: 0.6

db:BUGTRAQid:20081208 [SVRT-07-08] VULNERABILITY IN FACE RECOGNITION AUTHENTICATION MECHANISM OF LENOVO-ASUS-TOSHIBA LAPTOPS

Trust: 0.6

db:VULHUBid:VHN-38102

Trust: 0.1

sources: VULHUB: VHN-38102 // BID: 32700 // JVNDB: JVNDB-2009-003257 // CNNVD: CNNVD-200902-478 // NVD: CVE-2009-0656

REFERENCES

url:http://www.securityfocus.com/bid/32700

Trust: 1.7

url:http://www.securityfocus.com/archive/1/498997

Trust: 1.7

url:http://security.bkis.vn/?p=292

Trust: 1.7

url:http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#nguyen

Trust: 1.7

url:http://www.blackhat.com/presentations/bh-dc-09/nguyen/blackhat-dc-09-nguyen-face-not-your-password.pdf

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/48962

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-0656

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-0656

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/48962

Trust: 0.6

url:http://www.lenovo.com/ca/en/

Trust: 0.3

url:http://www.toshiba.com/

Trust: 0.3

url:/archive/1/498997

Trust: 0.3

url:http://www.asus.com/

Trust: 0.3

sources: VULHUB: VHN-38102 // BID: 32700 // JVNDB: JVNDB-2009-003257 // CNNVD: CNNVD-200902-478 // NVD: CVE-2009-0656

CREDITS

Nhat Minh, Nguyen Minh Duc, Bui Quang Minh and Le Minh Hung

Trust: 0.9

sources: BID: 32700 // CNNVD: CNNVD-200902-478

SOURCES

db:VULHUBid:VHN-38102
db:BIDid:32700
db:JVNDBid:JVNDB-2009-003257
db:CNNVDid:CNNVD-200902-478
db:NVDid:CVE-2009-0656

LAST UPDATE DATE

2025-04-10T23:15:38.591000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-38102date:2017-08-17T00:00:00
db:BIDid:32700date:2009-03-05T21:26:00
db:JVNDBid:JVNDB-2009-003257date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200902-478date:2009-06-09T00:00:00
db:NVDid:CVE-2009-0656date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-38102date:2009-02-20T00:00:00
db:BIDid:32700date:2008-12-08T00:00:00
db:JVNDBid:JVNDB-2009-003257date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200902-478date:2009-02-20T00:00:00
db:NVDid:CVE-2009-0656date:2009-02-20T19:30:00.360