CVE-2019-12813: Medium severity crossmatch digital persona u.are.u 4500 vulnerability
An issue was discovered in Digital Persona U.are.U 4500 Fingerprint Reader v24. The key and salt used for obfuscating the fingerprint image exhibit cleartext when the fingerprint scanner device transfers a fingerprint image to the driver. An attacker who sniffs an encrypted fingerprint image can easily decrypt that image using the key and salt.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12813?
CVE-2019-12813 is considered a high-severity vulnerability due to the exposure of sensitive fingerprint data.
How do I fix CVE-2019-12813?
To mitigate CVE-2019-12813, update to the latest version of the Digital Persona U.are.U 4500 firmware that addresses this vulnerability.
What does CVE-2019-12813 affect?
CVE-2019-12813 affects the Digital Persona U.are.U 4500 Fingerprint Reader firmware version 24.
What is the exploitation risk of CVE-2019-12813?
The exploitation risk of CVE-2019-12813 includes potential unauthorized access to sensitive fingerprint data.
Can CVE-2019-12813 lead to further attacks?
Yes, CVE-2019-12813 can lead to identity theft or unauthorized actions if the fingerprint images are compromised.