These systems, designed to control building access through authentication methods like passwords, biometrics, and multi-factor authentication, have been found to contain critical configuration errors that leave sensitive data exposed and facilities vulnerable to unauthorized entry. Security experts emphasize that such exposed data creates an expansive attack surface for various cyber threats including phishing campaigns, identity theft, social engineering attacks, and specialized fraud schemes designed to siphon additional sensitive information from organizations and individuals. Researchers at Heise Online discovered numerous cases where employee photographs, full names, identification numbers, access card details, biometric data, vehicle license plates, work schedules, and even facility access credentials were left completely unprotected and accessible to potential attackers. Connection requests to these vulnerable systems often return sensitive data in unencrypted format without proper authentication challenges, creating trivial exploitation vectors for even unsophisticated attackers. Dutch IT security consultancy Modat has uncovered alarming security vulnerabilities in approximately 49,000 access management systems (AMS) deployed worldwide. When improperly configured, these systems create dual threats: unauthorized physical access to buildings and unauthorized digital access to sensitive information stored within these systems. Authentication protocols in affected systems reveal consistent misconfiguration patterns that create exploitable security gaps. Access management systems authenticate users through various methods and authorize access rights based on predetermined policies. The geographic distribution of vulnerable systems shows concerning patterns with the highest concentration found in Europe, the United States, the Middle East, and North Africa. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 04 Mar 2025 18:10:05 +0000