7.1

CVE-2021-3675

Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synaptics Synaptics Fingerprint Driver 5.1.xxx.26 versions prior to xxx=340 on x86/64; 5.2.xxxx.26 versions prior to xxxx=3541 on x86/64; 5.2.2xx.26 versions prior to xx=29 on x86/64; 5.2.3xx.26 versions prior to xx=25 on x86/64; 5.3.xxxx.26 versions prior to xxxx=3543 on x86/64; 5.5.xx.1058 versions prior to xx=44 on x86/64; 5.5.xx.1102 versions prior to xx=34 on x86/64; 5.5.xx.1116 versions prior to xx=14 on x86/64; 6.0.xx.1104 versions prior to xx=50 on x86/64; 6.0.xx.1108 versions prior to xx=31 on x86/64; 6.0.xx.1111 versions prior to xx=58 on x86/64.

Data is provided by the National Vulnerability Database (NVD)
SynapticsFingerprint Driver Version >= 5.1.000.26 < 5.1.340.26
SynapticsFingerprint Driver Version >= 5.2.0000.26 < 5.2.3541.26
SynapticsFingerprint Driver Version >= 5.2.200.26 < 5.2.229.26
SynapticsFingerprint Driver Version >= 5.2.300.26 < 5.2.325.26
SynapticsFingerprint Driver Version >= 5.3.0000.26 < 5.3.3543.26
SynapticsFingerprint Driver Version >= 5.5.00.1058 < 5.5.44.1058
SynapticsFingerprint Driver Version >= 5.5.00.1102 < 5.5.34.1102
SynapticsFingerprint Driver Version >= 5.5.00.1116 < 5.5.14.1116
SynapticsFingerprint Driver Version >= 6.0.00.1111 < 6.0.58.1111
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.111
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvd@nist.gov 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:N/A:P
PSIRT@synaptics.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.