FB pixel

Acronis reports critical flaws in GeoVision biometric devices, man-in-the-middle attack risks

 

access-control

During a network security audit in 2019, cybersecurity company Acronis detected critical vulnerabilities in devices manufactured by biometrics company GeoVision, reports the security company, which has been waiting for the company to patch the flaws for almost a year.

The security company says it found a backdoor password with admin privileges, and claims GeoVision reuses cryptographic keys and discloses private keys. These flaws could enable traffic interception by state-sponsored attackers. The research was conducted by Acronis CISO Kevin Reed, and security researchers Alex Koshelev and Ravikant Tiwari.

The vulnerabilities were identified in fingerprint scanners, access card scanners, and access management appliances spread out in multiple countries. These devices are visible on Shodan and located in Brazil, the U.S., Germany, Taiwan, and Japan.

The key technical findings include undocumented hardcoded passwords which make it easy to access the device with root privileges, shared cryptographic keys in firmware which exposes the device to man-in-the-middle attacks, a buffer overflow vulnerability which can be manipulated to run unauthorized code without prior authentication, and information disclosure vulnerability that hackers can manipulate to read system logs.

Acronis informed GeoVision about the vulnerabilities in August 2019 and then in September about the 90-day courtesy period. Two months later, Acronis reported the vulnerabilities to the Singapore Computer Emergency Response Team (SingCERT). SingCERT and Taiwan’s TWCERT requested a one-month delay in making the vulnerabilities public.

Nearly a year later, in June 2020, three vulnerabilities were patched, yet the critical buffer overflow zero-day “wormable” vulnerability is still active and there is no firmware update. Hackers can overrun the memory buffer and manipulate it to tamper with device by rewriting protocols and commands.

Acronis says GeoVision has not commented or confirmed the findings.

Article Topics

 |   |   |   | 

Latest Biometrics News

 

ICE using data and probability to decide where to detain and arrest people

U.S. Immigration and Customs Enforcement’s Enhanced Leads Identification & Targeting for Enforcement (ELITE) tool is being used to identify “targets”…

 

In AI era, identity is about governance, Microblink’s Hartley Thompson tells BU Podcast

“One of the defining things in my life is change,” says Hartley Thompson of Microblink. “How do you react to…

 

CLR Labs wins funding to support biometrics, IAD, digital wallet standardization

Cabinet Louis Reynaud (CLR Labs) has won funding from a French government program to support its standardization efforts in biometrics,…

 

Checkr crossed $800M gross in 2025 as biometric background checks expand

Biometric background check provider Checkr is celebrating 2025 as its most successful year ever, with gross revenue surpassing $800 million…

 

Identity and risk infrastructure startup secures $12M for Europe, LATAM expansion

Monnai, which provides identity and risk data infrastructure, has announced a 12 million dollar equity funding round led by Motive…

 

Hopae appoints Sarah Clark to lead US expansion of digital ID verification platform

Sarah Clark is Hopae’s new CPO and GM for North America, joining the Seoul-headquartered company to help extend the reach…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events