CVE-2021-35522
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP MD devices before 4.9.7 allows remote attackers to achieve code execution, denial of services, and information disclosure via TCP/IP packets.
Affected (11)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.2 |
| Running on/with | Platform Versions |
|---|---|
Idemia Morphowave Compact Mdpi | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.2 |
| Running on/with | Platform Versions |
|---|---|
Idemia Morphowave Compact Mdpi M | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.2 |
| Running on/with | Platform Versions |
|---|---|
Idemia Visionpass Mdpi | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.2 |
| Running on/with | Platform Versions |
|---|---|
Idemia Visionpass Mdpi M | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Idemia Sigma Lite | Version 4.9.4 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Idemia Sigma Lite+ | Version 4.9.4 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Idemia Sigma Wide | Version 4.9.4 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Idemia Sigma Extreme | Version 4.9.4 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Idemia Ma Vp Md | Version 4.9.7 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Idemia Visionpass Md | Version 2.6.2 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Idemia Morphowave Compact Md | Version 2.6.2 |
References (6)
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.