MEDIUM
Encryption key derived from static host information
Published Jan 27, 2024
5.2
MEDIUMCVSS 3.1
EPSS 0.13%
Description
Use of encryption key derived from static information in Synaptics Fingerprint Driver allows
an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an attacker, who has physical access to the sensor, to enroll a fingerprint into the template database.
Affected products
-
Affected
- ≥ 6.0.0.1103, < 6.0.17.1103
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Synaptics | Synaptics Fingerprint Driver | unknown | Affected
|
- ≥ 6.0.00.1103 · < 6.0.17.1103
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58714 Advisory
- https://www.synaptics.com/sites/default/files/2024-01/fingerprint-driver-encryption-key-security-brief-2024-01-26.pdf vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58714 | Advisory | |
| https://www.synaptics.com/sites/default/files/2024-01/fingerprint-driver-encryption-key-security-brief-2024-01-26.pdf | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Synaptics
Published Jan 27, 2024
Updated Oct 18, 2024
Reserved Dec 4, 2023
Link CVE-2023-6482
CISA Vulnrichment
Updated Oct 18, 2024
Red Hat
No data
GitHub
No data