Vulnerability Description
The Face authentication component in Aware mobile liveness 2.2.1 sdk 2.2.0 for Knomi allows a Biometrical Liveness authentication bypass via parameter tampering of the /knomi/analyze security_level field.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aware | Knomi | 2.2.0 |
References
- https://cxsecurity.com/issue/WLB-2019050166Third Party Advisory
- https://drive.google.com/open?id=1-0X8foCwjR3RmL_7UJcgOFYrwKOjYZQLExploitThird Party Advisory
- https://ibb.co/n7LS34gExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2019050166Third Party Advisory
- https://drive.google.com/open?id=1-0X8foCwjR3RmL_7UJcgOFYrwKOjYZQLExploitThird Party Advisory
- https://ibb.co/n7LS34gExploitThird Party Advisory
FAQ
What is CVE-2019-9196?
CVE-2019-9196 is a vulnerability with a CVSS score of 7.5 (HIGH). The Face authentication component in Aware mobile liveness 2.2.1 sdk 2.2.0 for Knomi allows a Biometrical Liveness authentication bypass via parameter tampering of the /knomi/analyze security_level fi...
How severe is CVE-2019-9196?
CVE-2019-9196 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-9196?
Check the references section above for vendor advisories and patch information. Affected products include: Aware Knomi.