← Back

CVE-2021-3675

nvd nist
Published: Jun 16, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synaptics Synaptics Fingerprint Driver 5.1.xxx.26 versions prior to xxx=340 on x86/64; 5.2.xxxx.26 versions prior to xxxx=3541 on x86/64; 5.2.2xx.26 versions prior to xx=29 on x86/64; 5.2.3xx.26 versions prior to xx=25 on x86/64; 5.3.xxxx.26 versions prior to xxxx=3543 on x86/64; 5.5.xx.1058 versions prior to xx=44 on x86/64; 5.5.xx.1102 versions prior to xx=34 on x86/64; 5.5.xx.1116 versions prior to xx=14 on x86/64; 6.0.xx.1104 versions prior to xx=50 on x86/64; 6.0.xx.1108 versions prior to xx=31 on x86/64; 6.0.xx.1111 versions prior to xx=58 on x86/64.

Affected (9)

1 product
Fingerprint Driver
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Synaptics
From 5.1.000.26 to 5.1.340.26
From 5.2.0000.26 to 5.2.3541.26
From 5.2.200.26 to 5.2.229.26
From 5.2.300.26 to 5.2.325.26
From 5.3.0000.26 to 5.3.3543.26
From 5.5.00.1058 to 5.5.44.1058
From 5.5.00.1102 to 5.5.34.1102
From 5.5.00.1116 to 5.5.14.1116
From 6.0.00.1111 to 6.0.58.1111

References (6)

Source: PSIRT@synaptics.com
PatchThird Party Advisory
Source: PSIRT@synaptics.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.