4.3
CVSSv2

CVE-2019-13603

Published: 16/07/2019 Updated: 13/09/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5. It has a statically coded initialization vector to encrypt a user's fingerprint image, resulting in weak encryption of that. This, in combination with retrieving an encrypted fingerprint image and encryption key (through another vulnerability), allows an malicious user to obtain a user's fingerprint image.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hidglobal digital_persona_u.are.u_4500_driver_firmware 5.0.0.5

Github Repositories

Multiple Vulnerabilities in UareU 4500 Fingerprint Reader and its Linux/Windows Drivers Cleartext transmission of sensitive information (eg, encryption key) Use of insufficiently random values when generating initialization vector Basic Operation When a user try to use fingerprint authentication, a user might touch a finger on the fingerprint reader device Just after the