7.5
CVE-2023-33217
- EPSS 0.12%
- Veröffentlicht 15.12.2023 11:15:08
- Zuletzt bearbeitet 21.11.2024 08:05:09
- Quelle a87f365f-9d39-4848-9b3a-58c7ca
- CVE-Watchlists
- Unerledigt
By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the terminal. the only way to recover the terminal is by sending back the terminal to the manufacturer
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Idemia ≫ Sigma Lite Firmware Version < 4.15.5
Idemia ≫ Sigma Lite+ Firmware Version < 4.15.5
Idemia ≫ Sigma Extreme Firmware Version < 4.15.5
Idemia ≫ Sigma Wide Firmware Version < 4.15.5
Idemia ≫ Morphowave Compact Firmware Version < 2.12.2
Idemia ≫ Morphowave Xp Firmware Version < 2.12.2
Idemia ≫ Visionpass Firmware Version < 2.12.2
Idemia ≫ Morphowave Sp Firmware Version < 1.2.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.317 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| a87f365f-9d39-4848-9b3a-58c7cae69cab | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.