PT-2021-6029 · Idemia · Idemia Morpho Wave Compact+1

Published

2021-04-26

·

Updated

2021-08-06

·

CVE-2021-35521

CVSS v2.0

6.2

Medium

VectorAV:N/AC:H/Au:M/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions IDEMIA Morpho Wave Compact and VisionPass devices versions prior to 2.6.2
Description The issue is related to a path traversal in Thrift command handlers, allowing remote authenticated attackers to achieve denial of services and information disclosure via TCP/IP packets. This can enable an attacker to read or write files on the device.
Recommendations For versions prior to 2.6.2, update to version 2.6.2 or later to resolve the issue.

Fix

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00603
CVE-2021-35521

Affected Products

Idemia Morpho Visionpass
Idemia Morpho Wave Compact