CVE-2019-13603
It has a statically coded initialization vector to encrypt a user's fingerprint image, resulting in weak encryption of that.
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5. It has a statically coded initialization vector to encrypt a user's fingerprint image, resulting in weak encryption of that. This, in combination with retrieving an encrypted fingerprint image and encryption key (through another vulnerability), allows an attacker to obtain a user's fingerprint image.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-330
- Affected
- hidglobal/digital persona u.are.u 4500 driver firmware
- Source
- cve@mitre.org
References
- https://github.com/sungjungk/fp-scanner-hackingExploit, Third Party Advisory
- https://www.youtube.com/watch?v=Grirez2xeasExploit, Third Party Advisory
- https://www.youtube.com/watch?v=wEXJDyEOatMExploit, Third Party Advisory
- https://github.com/sungjungk/fp-scanner-hackingExploit, Third Party Advisory
- https://www.youtube.com/watch?v=Grirez2xeasExploit, Third Party Advisory
- https://www.youtube.com/watch?v=wEXJDyEOatMExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.