CVE-2023-6482: Encryption key derived from static host information
Use of encryption key derived from static information in Synaptics Fingerprint Driver allows
an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an attacker, who has physical access to the sensor, to enroll a fingerprint into the template database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6482?
CVE-2023-6482 has a critical severity as it allows an attacker with physical access to the fingerprint sensor to send restricted commands.
How do I fix CVE-2023-6482?
To mitigate CVE-2023-6482, users should update the Synaptics Fingerprint Driver to the latest version that addresses this vulnerability.
Who is affected by CVE-2023-6482?
CVE-2023-6482 affects users of the Synaptics Fingerprint Driver versions prior to 6.0.17.1103.
What are the potential consequences of CVE-2023-6482?
The potential consequences of CVE-2023-6482 include unauthorized access and manipulation of the fingerprint sensor which may lead to bypassing authentication measures.
Is physical access required to exploit CVE-2023-6482?
Yes, an attacker must have physical access to the fingerprint sensor to exploit CVE-2023-6482.