CVE-2017-15567

The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via unspecified vectors. NOTE: the vendor disputes this because there is no command shell in the product or in the associated SDK
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:idemia:mso_1300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:idemia:mso_1300:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:14

Type Values Removed Values Added
References () https://gist.github.com/shiham101/4c49ece8ecac7c3c02ecbc6942aeca80 - Third Party Advisory () https://gist.github.com/shiham101/4c49ece8ecac7c3c02ecbc6942aeca80 - Third Party Advisory

07 Nov 2023, 02:40

Type Values Removed Values Added
Summary ** DISPUTED ** The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via unspecified vectors. NOTE: the vendor disputes this because there is no command shell in the product or in the associated SDK. The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via unspecified vectors. NOTE: the vendor disputes this because there is no command shell in the product or in the associated SDK

Information

Published : 2017-10-23 08:29

Updated : 2024-11-21 03:14


NVD link : CVE-2017-15567

Mitre link : CVE-2017-15567

CVE.ORG link : CVE-2017-15567


JSON object : View

Products Affected

idemia

  • mso_1300
  • mso_1300_firmware