Vulnerabilities (CVE)

Filtered by vendor Idemia Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-4667 1 Idemia 12 Morphowave Compact, Morphowave Compact Firmware, Morphowave Sp and 9 more 2023-12-05 N/A 4.8 MEDIUM
The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface.  The root cause of the vulnerability is inadequate input validation and output encoding in the web administration interface component of the firmware. This could lead to  unauthorized access and data leakage
CVE-2021-35520 1 Idemia 8 Morphowave Compact Mdpi, Morphowave Compact Mdpi-m, Morphowave Compact Mdpi-m Firmware and 5 more 2021-08-06 4.6 MEDIUM 6.2 MEDIUM
A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows physically proximate authenticated attackers to achieve code execution, denial of services, and information disclosure via serial ports.
CVE-2021-35521 1 Idemia 12 Morphowave Compact Md, Morphowave Compact Md Firmware, Morphowave Compact Mdpi and 9 more 2021-08-06 4.9 MEDIUM 5.9 MEDIUM
A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows remote authenticated attackers to achieve denial of services and information disclosure via TCP/IP packets.