Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sigma Lite Firmware CRITICAL 9.8
CVE-2023-33222

When handling contactless cards, usage of a specific function to get additional information from the card which doesn't check the boundary on the da…

Fix: 1.2.7 / 2.12.2+
Fix from $2,300 2023-12-15
Sigma Lite Firmware CRITICAL 9.8
CVE-2023-33218

The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. This could potentially lead to a Remote …

Fix: 1.2.7 / 2.12.2+
Fix from $2,300 2023-12-15
Sigma Lite Firmware CRITICAL 9.8
CVE-2023-33219

The handler of the retrofit validation command doesn't properly check the boundaries when performing certain validation operations. This allows a st…

Fix: 1.2.7 / 2.12.2+
Fix from $2,300 2023-12-15
Sigma Lite Firmware CRITICAL 9.8
CVE-2023-33220

During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some attributes to check. This allows a sta…

Fix: 1.2.7 / 2.12.2+
Fix from $2,300 2023-12-15
Sigma Lite Firmware CRITICAL 9.8
CVE-2023-33221

When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This a…

Fix: 1.2.7 / 2.12.2+
Fix from $2,300 2023-12-15
Sigma Lite Firmware HIGH 7.5
CVE-2023-33217

By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the ter…

Fix: 1.2.7 / 2.12.2+
Fix from $1,950 2023-12-15
Morphowave Compact Mdpi Firmware CRITICAL 9.8
CVE-2021-35522

A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP…

Fix: 2.6.2+
Fix from $2,300 2021-07-22
Morphowave Compact Mdpi Firmware MEDIUM 6.2
CVE-2021-35520

A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows physically proximate authentica…

Fix: 2.6.2+
Fix from $1,600 2021-07-22
Morphowave Compact Mdpi Firmware MEDIUM 5.9
CVE-2021-35521

A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows remote authenticated attackers t…

Fix: 2.6.2+
Fix from $1,600 2021-07-22
Mso 1300 Firmware HIGH 7.8
CVE-2017-15567

The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a com…

Mitigation only
Fix from $1,950 2017-10-23