Critical severity9.8NVD Advisory· Published Jul 22, 2021· Updated Jun 17, 2026
CVE-2021-35522
CVE-2021-35522
Description
A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP MD devices before 4.9.7 allows remote attackers to achieve code execution, denial of services, and information disclosure via TCP/IP packets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16- IDEMIA/Morpho Wave Compact and VisionPass devicesdescription
- Range: <2.6.2
- Range: <2.6.2
- cpe:2.3:o:idemia:morphowave_compact_mdpi_firmware:*:*:*:*:*:*:*:*Range: <2.6.2
- cpe:2.3:o:idemia:morphowave_compact_mdpi-m_firmware:*:*:*:*:*:*:*:*Range: <2.6.2
- cpe:2.3:o:idemia:visionpass_mdpi_firmware:*:*:*:*:*:*:*:*Range: <2.6.2
- cpe:2.3:o:idemia:visionpass_mdpi-m_firmware:*:*:*:*:*:*:*:*Range: <2.6.2
- cpe:2.3:o:idemia:visionpass_md_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:idemia:morphowave_compact_md_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_lite_firmware:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:idemia:sigma_lite_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:idemia:sigma_lite\+_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:idemia:sigma_wide_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:idemia:sigma_extreme_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:idemia:ma_vp_md_firmware:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- biometricdevices.idemia.com/s/global-search/0696700000JJa0zAADnvdPatchVendor Advisory
- biometricdevices.idemia.com/s/global-search/0696700000JJa1nAADnvdPatchVendor Advisory
- www.idemia.comnvdProduct
News mentions
0No linked articles in our index yet.