← Back

CVE-2021-35520

nvd nist
Published: Jul 22, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.2
Vector
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.3 / Impact: 5.9
Source: NVD

Description

A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows physically proximate authenticated attackers to achieve code execution, denial of services, and information disclosure via serial ports.

Affected (4)

4 products
Morphowave Compact Mdpi Firmware
Visionpass Mdpi Firmware
Visionpass Mdpi M Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.6.2
Running on/withPlatform Versions
Idemia
Morphowave Compact Mdpi
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.6.2
Running on/withPlatform Versions
Idemia
Morphowave Compact Mdpi M
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.6.2
Running on/withPlatform Versions
Idemia
Visionpass Mdpi
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.6.2
Running on/withPlatform Versions
Idemia
Visionpass Mdpi M
All versions

References (6)

Source: cve@mitre.org
Product
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.