A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows physically proximate authenticated attackers to achieve code execution, denial of services, and information disclosure via serial ports.
References
Link | Resource |
---|---|
https://biometricdevices.idemia.com/s/global-search/0696700000JJa0zAAD?sharing=true | Patch Vendor Advisory |
https://biometricdevices.idemia.com/s/global-search/0696700000JJa1nAAD?sharing=true | Patch Vendor Advisory |
https://www.idemia.com | Product |
https://biometricdevices.idemia.com/s/global-search/0696700000JJa0zAAD?sharing=true | Patch Vendor Advisory |
https://biometricdevices.idemia.com/s/global-search/0696700000JJa1nAAD?sharing=true | Patch Vendor Advisory |
https://www.idemia.com | Product |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
21 Nov 2024, 06:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://biometricdevices.idemia.com/s/global-search/0696700000JJa0zAAD?sharing=true - Patch, Vendor Advisory | |
References | () https://biometricdevices.idemia.com/s/global-search/0696700000JJa1nAAD?sharing=true - Patch, Vendor Advisory | |
References | () https://www.idemia.com - Product |
Information
Published : 2021-07-22 12:15
Updated : 2024-11-21 06:12
NVD link : CVE-2021-35520
Mitre link : CVE-2021-35520
CVE.ORG link : CVE-2021-35520
JSON object : View
Products Affected
idemia
- morphowave_compact_mdpi
- morphowave_compact_mdpi-m_firmware
- visionpass_mdpi_firmware
- visionpass_mdpi-m_firmware
- morphowave_compact_mdpi-m
- visionpass_mdpi-m
- visionpass_mdpi
- morphowave_compact_mdpi_firmware
CWE
CWE-787
Out-of-bounds Write