Security Advisory

CVE-2019-13603

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-07-16 16:52:31
Last updated 2024-08-04 23:57:39
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5. It has a statically coded initialization vector to encrypt a user's fingerprint image, resulting in weak encryption of that. This, in combination with retrieving an encrypted fingerprint image and encryption key (through another vulnerability), allows an attacker to obtain a user's fingerprint image.