CVE-2021-35521
22.07.2021, 12:15
A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows remote authenticated attackers to achieve denial of services and information disclosure via TCP/IP packets.
| Vendor | Product | Version |
|---|---|---|
| idemia | morphowave_compact_mdpi_firmware | 𝑥 < 2.6.2 |
| idemia | morphowave_compact_mdpi-m_firmware | 𝑥 < 2.6.2 |
| idemia | visionpass_mdpi_firmware | 𝑥 < 2.6.2 |
| idemia | visionpass_mdpi-m_firmware | 𝑥 < 2.6.2 |
| idemia | visionpass_md_firmware | - |
| idemia | morphowave_compact_md_firmware | - |
𝑥
= Vulnerable software versions
References