PT-2019-5808 · Hid Global · Hid Global Digitalpersona U.Are.U 4500 Fingerprint Reader

Published

2019-03-23

·

Updated

2021-09-13

·

CVE-2019-13603

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HID Global DigitalPersona U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver version 5.0.0.5
Description The issue is related to errors in cryptographic transformations in the driver, which results in weak encryption of a user's fingerprint image. This weakness, combined with another vulnerability that allows retrieval of the encrypted fingerprint image and encryption key, enables an attacker to obtain a user's fingerprint image. The vulnerability may allow a remote attacker to gain unauthorized access to protected information.
Recommendations For version 5.0.0.5, consider disabling the use of the statically coded initialization vector until a patch is available. Restrict access to the fingerprint image encryption functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02996
CVE-2019-13603

Affected Products

Hid Global Digitalpersona U.Are.U 4500 Fingerprint Reader