{ "schema_version": "1.4.0", "id": "GHSA-cw24-63qh-x675", "modified": "2022-05-24T16:50:29Z", "published": "2022-05-24T16:50:29Z", "aliases": [ "CVE-2019-13603" ], "details": "An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5. It has a statically coded initialization vector to encrypt a user's fingerprint image, resulting in weak encryption of that. This, in combination with retrieving an encrypted fingerprint image and encryption key (through another vulnerability), allows an attacker to obtain a user's fingerprint image.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13603" }, { "type": "WEB", "url": "https://github.com/sungjungk/fp-scanner-hacking" }, { "type": "WEB", "url": "https://www.youtube.com/watch?v=Grirez2xeas" }, { "type": "WEB", "url": "https://www.youtube.com/watch?v=wEXJDyEOatM" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-07-16T17:15:00Z" } }