PT-2019-5808 · Hid Global · Hid Global Digitalpersona U.Are.U 4500 Fingerprint Reader
Published
2019-03-23
·
Updated
2021-09-13
·
CVE-2019-13603
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HID Global DigitalPersona U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver version 5.0.0.5
Description
The issue is related to errors in cryptographic transformations in the driver, which results in weak encryption of a user's fingerprint image. This weakness, combined with another vulnerability that allows retrieval of the encrypted fingerprint image and encryption key, enables an attacker to obtain a user's fingerprint image. The vulnerability may allow a remote attacker to gain unauthorized access to protected information.
Recommendations
For version 5.0.0.5, consider disabling the use of the statically coded initialization vector until a patch is available. Restrict access to the fingerprint image encryption functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hid Global Digitalpersona U.Are.U 4500 Fingerprint Reader