** DISPUTED ** The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via unspecified vectors. NOTE: the vendor disputes this because there is no command shell in the product or in the associated SDK.
References
Link | Resource |
---|---|
https://gist.github.com/shiham101/4c49ece8ecac7c3c02ecbc6942aeca80 | Third Party Advisory |
https://gist.github.com/shiham101/4c49ece8ecac7c3c02ecbc6942aeca80 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 03:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/shiham101/4c49ece8ecac7c3c02ecbc6942aeca80 - Third Party Advisory |
23 Jun 2021, 17:28
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:morpho:mso_1300:-:*:*:*:*:*:*:* |
cpe:2.3:o:idemia:mso_1300_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:idemia:mso_1300:-:*:*:*:*:*:*:* |
Information
Published : 2017-10-23 08:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-15567
Mitre link : CVE-2017-15567
CVE.ORG link : CVE-2017-15567
JSON object : View
Products Affected
idemia
- mso_1300_firmware
- mso_1300
CWE