VYPR
Medium severity5.2NVD Advisory· Published Jan 27, 2024· Updated Jun 17, 2026

CVE-2023-6482

CVE-2023-6482

Description

Use of encryption key derived from static information in Synaptics Fingerprint Driver allows

an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an attacker, who has physical access to the sensor, to enroll a fingerprint into the template database.

Affected products

3
  • cpe:2.3:a:synaptics:fingerprint_driver:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:synaptics:fingerprint_driver:*:*:*:*:*:*:*:*range: >=6.0.00.1103,<6.0.17.1103
    • (no CPE)
    • (no CPE)range: 6.0.0.1103

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.