This Metasploit module attempts to gain root privileges on systems running MagniComp SysInfo versions prior to 10-H64. The .mcsiwrapper suid executable allows loading a config file using the '--configfile' argument. The 'ExecPath' config directive is used to set the executable load path. This Metasploit module abuses this functionality to set the load path resulting in execution of arbitrary code as root. This Metasploit module has been tested successfully with SysInfo version 10-H63 on Fedora 20 x86_64, 10-H32 on Fedora 27 x86_64, 10-H10 on Debian 8 x86_64, and 10-GA on Solaris 10u11 x86.
809ebb68ed1aab5bb488f6d63c6c587cf594c965eb2d13367633fdff06cc093e
FingerTec devices have a default root password that allows for remote enrollment.
a8567f878bdec6acc2d742b90abb6aaff946e2de70df870e144ec1b61be4cd74