SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-12813

An attacker who sniffs an encrypted fingerprint image can easily decrypt that image using the key and salt.

MEDIUM 5.9EPSS 1.13%

Does this matter?

Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Digital Persona U.are.U 4500 Fingerprint Reader v24. The key and salt used for obfuscating the fingerprint image exhibit cleartext when the fingerprint scanner device transfers a fingerprint image to the driver. An attacker who sniffs an encrypted fingerprint image can easily decrypt that image using the key and salt.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.13% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-319
Affected
crossmatch/digital persona u.are.u 4500 firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.