Back

MEDIUM

Encryption key derived from static host information

Published Jan 27, 2024

Description

Use of encryption key derived from static information in Synaptics Fingerprint Driver allows

an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an attacker, who has physical access to the sensor, to enroll a fingerprint into the template database.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Synaptics
Published Jan 27, 2024
Updated Oct 18, 2024
Reserved Dec 4, 2023

CISA Vulnrichment

Updated Oct 18, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Synaptics
Published Jan 27, 2024
Updated Oct 18, 2024

GitHub

No data