9.8

CVE-2021-35522

A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP MD devices before 4.9.7 allows remote attackers to achieve code execution, denial of services, and information disclosure via TCP/IP packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IdemiaVisionpass Mdpi Firmware Version < 2.6.2
   IdemiaVisionpass Mdpi Version-
IdemiaVisionpass Mdpi-m Firmware Version < 2.6.2
   IdemiaVisionpass Mdpi-m Version-
IdemiaVisionpass Md Firmware Version-
   IdemiaVisionpass Md Version2.6.2
IdemiaSigma Lite Firmware Version-
   IdemiaSigma Lite Version4.9.4
IdemiaSigma Lite+ Firmware Version-
   IdemiaSigma Lite+ Version4.9.4
IdemiaSigma Wide Firmware Version-
   IdemiaSigma Wide Version4.9.4
IdemiaSigma Extreme Firmware Version-
   IdemiaSigma Extreme Version4.9.4
IdemiaMa Vp Md Firmware Version-
   IdemiaMa Vp Md Version4.9.7
IdemiaVisionpass Md Firmware Version-
   IdemiaVisionpass Md Version2.6.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.1% 0.881
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 10 8.5
AV:N/AC:L/Au:N/C:P/I:P/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.