A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows physically proximate authenticated attackers to achieve code execution, denial of services, and information disclosure via serial ports.
References
Link | Resource |
---|---|
https://biometricdevices.idemia.com/s/global-search/0696700000JJa0zAAD?sharing=true | Patch Vendor Advisory |
https://biometricdevices.idemia.com/s/global-search/0696700000JJa1nAAD?sharing=true | Patch Vendor Advisory |
https://www.idemia.com | Product |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
No history.
Information
Published : 2021-07-22 12:15
Updated : 2021-08-06 13:37
NVD link : CVE-2021-35520
Mitre link : CVE-2021-35520
CVE.ORG link : CVE-2021-35520
JSON object : View
Products Affected
idemia
- morphowave_compact_mdpi-m_firmware
- morphowave_compact_mdpi
- visionpass_mdpi-m
- morphowave_compact_mdpi_firmware
- visionpass_mdpi_firmware
- visionpass_mdpi-m_firmware
- visionpass_mdpi
- morphowave_compact_mdpi-m
CWE
CWE-787
Out-of-bounds Write