CVE-2021-35521
22.07.2021, 12:15
A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows remote authenticated attackers to achieve denial of services and information disclosure via TCP/IP packets.
Vendor | Product | Version |
---|---|---|
idemia | morphowave_compact_mdpi_firmware | 𝑥 < 2.6.2 |
idemia | morphowave_compact_mdpi-m_firmware | 𝑥 < 2.6.2 |
idemia | visionpass_mdpi_firmware | 𝑥 < 2.6.2 |
idemia | visionpass_mdpi-m_firmware | 𝑥 < 2.6.2 |
idemia | visionpass_md_firmware | - |
idemia | morphowave_compact_md_firmware | - |
𝑥
= Vulnerable software versions
References