PT-2021-6028 · Idemia · Idemia Morpho Wave Compact+1

Published

2021-04-26

·

Updated

2021-08-06

·

CVE-2021-35520

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IDEMIA Morpho Wave Compact and VisionPass devices versions prior to 2.6.2
Description The issue is related to a buffer overflow in Thrift command handlers, which can be exploited by physically proximate authenticated attackers to achieve code execution, denial of services, and information disclosure via serial ports. This can potentially allow an attacker to gain remote access to the device.
Recommendations For versions prior to 2.6.2, update to version 2.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the serial ports to minimize the risk of exploitation.

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00602
CVE-2021-35520

Affected Products

Idemia Morpho Visionpass
Idemia Morpho Wave Compact