CVE-2021-35522
9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP MD devices before 4.9.7 allows remote attackers to achieve code execution, denial of services, and information disclosure via TCP/IP packets.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.66% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-07-22 |
| Last modified | 2026-06-17 |
Affected (22)
| Vendor | Product |
|---|---|
| idemia | ma vp md |
| idemia | ma vp md firmware |
| idemia | morphowave compact md |
| idemia | morphowave compact md firmware |
| idemia | morphowave compact mdpi |
| idemia | morphowave compact mdpi firmware |
| idemia | morphowave compact mdpi-m |
| idemia | morphowave compact mdpi-m firmware |
| idemia | sigma extreme |
| idemia | sigma extreme firmware |
| idemia | sigma lite |
| idemia | sigma lite firmware |
| idemia | sigma lite\+ |
| idemia | sigma lite\+ firmware |
| idemia | sigma wide |
| idemia | sigma wide firmware |
| idemia | visionpass md |
| idemia | visionpass md firmware |
| idemia | visionpass mdpi |
| idemia | visionpass mdpi firmware |
| idemia | visionpass mdpi-m |
| idemia | visionpass mdpi-m firmware |
References
- https://biometricdevices.idemia.com/s/global-search/0696700000JJa0zAAD?sharing=true
- https://biometricdevices.idemia.com/s/global-search/0696700000JJa1nAAD?sharing=true
- https://www.idemia.com
- https://biometricdevices.idemia.com/s/global-search/0696700000JJa0zAAD?sharing=true
- https://biometricdevices.idemia.com/s/global-search/0696700000JJa1nAAD?sharing=true
- https://www.idemia.com
→ the Explorer · watch your stack · NVD