7.1
CVE-2021-3675
- EPSS 0.04%
- Published 16.06.2022 17:15:07
- Last modified 21.11.2024 06:22:08
- Source PSIRT@synaptics.com
- Teams watchlist Login
- Open Login
Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synaptics Synaptics Fingerprint Driver 5.1.xxx.26 versions prior to xxx=340 on x86/64; 5.2.xxxx.26 versions prior to xxxx=3541 on x86/64; 5.2.2xx.26 versions prior to xx=29 on x86/64; 5.2.3xx.26 versions prior to xx=25 on x86/64; 5.3.xxxx.26 versions prior to xxxx=3543 on x86/64; 5.5.xx.1058 versions prior to xx=44 on x86/64; 5.5.xx.1102 versions prior to xx=34 on x86/64; 5.5.xx.1116 versions prior to xx=14 on x86/64; 6.0.xx.1104 versions prior to xx=50 on x86/64; 6.0.xx.1108 versions prior to xx=31 on x86/64; 6.0.xx.1111 versions prior to xx=58 on x86/64.
Data is provided by the National Vulnerability Database (NVD)
Synaptics ≫ Fingerprint Driver Version >= 5.1.000.26 < 5.1.340.26
Synaptics ≫ Fingerprint Driver Version >= 5.2.0000.26 < 5.2.3541.26
Synaptics ≫ Fingerprint Driver Version >= 5.2.200.26 < 5.2.229.26
Synaptics ≫ Fingerprint Driver Version >= 5.2.300.26 < 5.2.325.26
Synaptics ≫ Fingerprint Driver Version >= 5.3.0000.26 < 5.3.3543.26
Synaptics ≫ Fingerprint Driver Version >= 5.5.00.1058 < 5.5.44.1058
Synaptics ≫ Fingerprint Driver Version >= 5.5.00.1102 < 5.5.34.1102
Synaptics ≫ Fingerprint Driver Version >= 5.5.00.1116 < 5.5.14.1116
Synaptics ≫ Fingerprint Driver Version >= 6.0.00.1111 < 6.0.58.1111
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.111 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
|
nvd@nist.gov | 3.6 | 3.9 | 4.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:P
|
PSIRT@synaptics.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.