The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via unspecified vectors. NOTE: the vendor disputes this because there is no command shell in the product or in the associated SDK
References
Link | Resource |
---|---|
https://gist.github.com/shiham101/4c49ece8ecac7c3c02ecbc6942aeca80 | Third Party Advisory |
https://gist.github.com/shiham101/4c49ece8ecac7c3c02ecbc6942aeca80 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 03:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/shiham101/4c49ece8ecac7c3c02ecbc6942aeca80 - Third Party Advisory |
07 Nov 2023, 02:40
Type | Values Removed | Values Added |
---|---|---|
Summary | The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via unspecified vectors. NOTE: the vendor disputes this because there is no command shell in the product or in the associated SDK |
Information
Published : 2017-10-23 08:29
Updated : 2024-11-21 03:14
NVD link : CVE-2017-15567
Mitre link : CVE-2017-15567
CVE.ORG link : CVE-2017-15567
JSON object : View
Products Affected
idemia
- mso_1300
- mso_1300_firmware
CWE