CVE-2021-35522
Summary
| CVE | CVE-2021-35522 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-22 12:15:00 UTC |
| Updated | 2021-08-09 16:57:00 UTC |
| Description | A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP MD devices before 4.9.7 allows remote attackers to achieve code execution, denial of services, and information disclosure via TCP/IP packets. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Idemia | Ma Vp Md | 4.9.7 | All | All | All |
| Operating System | Idemia | Ma Vp Md Firmware | - | All | All | All |
| Hardware | Idemia | Morphowave Compact Md | 2.6.2 | All | All | All |
| Hardware | Idemia | Morphowave Compact Mdpi | - | All | All | All |
| Hardware | Idemia | Morphowave Compact Mdpi-m | - | All | All | All |
| Operating System | Idemia | Morphowave Compact Mdpi-m Firmware | All | All | All | All |
| Operating System | Idemia | Morphowave Compact Mdpi Firmware | All | All | All | All |
| Operating System | Idemia | Morphowave Compact Md Firmware | - | All | All | All |
| Hardware | Idemia | Sigma Extreme | 4.9.4 | All | All | All |
| Operating System | Idemia | Sigma Extreme Firmware | - | All | All | All |
| Hardware | Idemia | Sigma Lite | 4.9.4 | All | All | All |
| Hardware | Idemia | Sigma Lite | 4.9.4 | All | All | All |
| Operating System | Idemia | Sigma Lite Firmware | - | All | All | All |
| Operating System | Idemia | Sigma Lite Firmware | - | All | All | All |
| Hardware | Idemia | Sigma Wide | 4.9.4 | All | All | All |
| Operating System | Idemia | Sigma Wide Firmware | - | All | All | All |
| Hardware | Idemia | Visionpass Md | 2.6.2 | All | All | All |
| Hardware | Idemia | Visionpass Mdpi | - | All | All | All |
| Hardware | Idemia | Visionpass Mdpi-m | - | All | All | All |
| Operating System | Idemia | Visionpass Mdpi-m Firmware | All | All | All | All |
| Operating System | Idemia | Visionpass Mdpi Firmware | All | All | All | All |
| Operating System | Idemia | Visionpass Md Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| The global leader in Augmented Identity | IDEMIA | MISC | www.idemia.com | |
| IDEMIA Biometric Devices Portal | MISC | biometricdevices.idemia.com | |
| IDEMIA Biometric Devices Portal | MISC | biometricdevices.idemia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.