4.3
CVSSv2

CVE-2019-13604

Published: 15/07/2019 Updated: 24/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24. The key for obfuscating the fingerprint image is vulnerable to brute-force attacks. This allows an malicious user to recover the key and decrypt that image using the key. Successful exploitation causes a sensitive biometric information leak.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

assaabloy hid_digitalpersona_4500_firmware 24

Github Repositories

PoC: encryption key cracking for UareU 4500 Fingerprint Reader It is a PoC to crack encrypted fingerprint image generated in UareU 4500 Fingerprint Reader Overview Digital Persona UareU 4500 is a fingerprint reader for authentication and identification solutions The manufacturer describes the product as follows (see [1]): To use, simply place a finger on the reader win