CVE-2019-13603
https://notcve.org/view.php?id=CVE-2019-13603
An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5. It has a statically coded initialization vector to encrypt a user's fingerprint image, resulting in weak encryption of that. This, in combination with retrieving an encrypted fingerprint image and encryption key (through another vulnerability), allows an attacker to obtain a user's fingerprint image. Se detectó un problema en el controlador versión 5.0.0.5 del Framework Biometric de Windows del U.are.U 4500 Fingerprint Reader de HID Global DigitalPersona (anteriormente Crossmatch). Tiene un vector de inicialización codificado estáticamente para cifrar la imagen de la huella digital de un usuario, resultando en un cifrado débil de esta. • https://github.com/sungjungk/fp-scanner-hacking https://www.youtube.com/watch?v=Grirez2xeas https://www.youtube.com/watch?v=wEXJDyEOatM • CWE-330: Use of Insufficiently Random Values •