SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-13603

It has a statically coded initialization vector to encrypt a user's fingerprint image, resulting in weak encryption of that.

MEDIUM 5.9EPSS 1.06%

Does this matter?

Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5. It has a statically coded initialization vector to encrypt a user's fingerprint image, resulting in weak encryption of that. This, in combination with retrieving an encrypted fingerprint image and encryption key (through another vulnerability), allows an attacker to obtain a user's fingerprint image.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.06% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-330
Affected
hidglobal/digital persona u.are.u 4500 driver firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.