6.2

CVE-2021-35520

A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows physically proximate authenticated attackers to achieve code execution, denial of services, and information disclosure via serial ports.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IdemiaVisionpass Mdpi Firmware Version < 2.6.2
   IdemiaVisionpass Mdpi Version-
IdemiaVisionpass Mdpi-m Firmware Version < 2.6.2
   IdemiaVisionpass Mdpi-m Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.254
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.2 0.3 5.9
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://biometricdevices.idemia.com/s/global-search/0696700000JJa0zAAD?sharing=true
Patch
Vendor Advisory
https://biometricdevices.idemia.com/s/global-search/0696700000JJa1nAAD?sharing=true
Patch
Vendor Advisory
https://www.idemia.com
Product