PT-2024-14964 · Synaptics · Synaptics Fingerprint Driver
Published
2024-01-26
·
Updated
2024-02-01
·
CVE-2023-6482
CVSS v3.1
5.2
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Synaptics Fingerprint Driver (affected versions not specified)
Description
The issue allows an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to it by using an encryption key derived from static information. This may enable an attacker with physical access to the sensor to enroll a fingerprint into the template database.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Synaptics Fingerprint Driver