An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data access can be bypassed. An attacker with physical access can send a static packet to a serial port exposed on the PCB to unlock the key and get access to the data without possessing the required fingerprint.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2018-03-22 08:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-16242
Mitre link : CVE-2017-16242
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
meco
- usb_memory_stick_with_fingerprint_firwmare
- usb_memory_stick_with_fingerprint