Description

IDEMIA, a global technology company located in France, released a security report informing about a critical vulnerability affecting several IDEMIA biometric identification devices that attackers may use to unlock doors and turnstiles by sending specific commands without authentication (if the TLS protocol is not activated). As per a warning provided by IDEMIA, the attacker may potentially leverage the vulnerability to trigger a denial of service (DoS) scenario by sending a reboot command to the affected device. MorphoWave Compact MD/MDPI/MDPI-M, SIGMA Extreme, VisionPass MD/MDPI/MDPI-M, all SIGMA Lite/Lite+/Wide versions, and MA VP MD are all affected by this flaw. This vulnerability also affects organizations that use vulnerable IDEMIA biometric identity devices, such as critical infrastructure facilities, health systems, financial institutions, and universities. Further, IDEMIA urged users to properly configure TLS protocol and install TLS certificate for the vulnerable devices to mitigate the cyberattacks.