PT-2017-14099 · Idemia · Idemia Morphosmart 1300 Series

Published

2017-10-23

·

Updated

2024-08-05

·

CVE-2017-15567

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IDEMIA MorphoSmart 1300 Series devices (affected versions not specified)
Description The certificate import component in IDEMIA MorphoSmart 1300 Series devices allows local users to obtain a command shell and gain privileges via unspecified vectors. It is noted that the vendor disputes this issue because there is no command shell in the product or in the associated SDK.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2017-15567

Affected Products

Idemia Morphosmart 1300 Series