VulnerabilityModified
CVE-2019-12813
An attacker who sniffs an encrypted fingerprint image can easily decrypt that image using the key and salt.
MEDIUM 5.9EPSS 1.13%
Does this matter?
Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Digital Persona U.are.U 4500 Fingerprint Reader v24. The key and salt used for obfuscating the fingerprint image exhibit cleartext when the fingerprint scanner device transfers a fingerprint image to the driver. An attacker who sniffs an encrypted fingerprint image can easily decrypt that image using the key and salt.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.13% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- crossmatch/digital persona u.are.u 4500 firmware
- Source
- cve@mitre.org
References
- https://github.com/sungjungk/fp-scanner-hackingExploit, Third Party Advisory
- https://www.youtube.com/watch?v=Grirez2xeasExploit, Third Party Advisory
- https://www.youtube.com/watch?v=wEXJDyEOatMExploit, Third Party Advisory
- https://github.com/sungjungk/fp-scanner-hackingExploit, Third Party Advisory
- https://www.youtube.com/watch?v=Grirez2xeasExploit, Third Party Advisory
- https://www.youtube.com/watch?v=wEXJDyEOatMExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.