Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5jr-34r4-rv4w

Опубликовано: 27 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.2

Описание

Use of encryption key derived from static information in Synaptics Fingerprint Driver allows

an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an attacker, who has physical access to the sensor, to enroll a fingerprint into the template database.

Use of encryption key derived from static information in Synaptics Fingerprint Driver allows

an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an attacker, who has physical access to the sensor, to enroll a fingerprint into the template database.

EPSS

Процентиль: 22%
0.00072
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-321
CWE-798

Связанные уязвимости

CVSS3: 5.2
nvd
около 2 лет назад

Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an attacker, who has physical access to the sensor, to enroll a fingerprint into the template database.

EPSS

Процентиль: 22%
0.00072
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-321
CWE-798