IDEMIA is a narrowly focused vendor of biometric and identity-verification hardware, including fingerprint scanners and related firmware products such as the Sigma Extreme and Sigma Wide lines. Its vulnerability exposure skews strongly toward critical-severity outcomes and concentrates in memory-safety weakness classes including out-of-bounds writes, stack and heap buffer overflows, and improper input validation—characteristic flaws in embedded credential-processing systems. Defenders should prioritize patches for these hardware platforms wherever they serve authentication or access-control functions; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by IDEMIA over time
Of all the CVEs published by IDEMIA as a CNA, 100.0% affect products that IDEMIA develops as a vendor.
Of all the CVEs published that affect products developed by IDEMIA, 63.6% are self-published by IDEMIA as a CNA.
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33219CRITICAL
The handler of the retrofit validation command doesn't properly check the boundaries when performing certain validation
operations. This allows a stack-based buffer overflow | Dec 15, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-35522CRITICAL A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP MD devices before 4.9.7 allows | Jul 22, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-33220CRITICAL
During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some attributes
to check. This allows a stack-based buffer overflow | Dec 15, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-33222CRITICAL
When handling contactless cards, usage of a specific function to get additional information from the card which doesn't
check the boundary on the data received while read | Dec 15, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-33218CRITICAL
The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow.
This could potentially lead to a Remote Code execution on the target | Dec 15, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-33221CRITICAL
When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying
internally the data received. This allows a heap based buf | Dec 15, 2023 | 9.8 | 27 | NO | NO |
CVE-2017-15567HIGH The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently ga | Oct 23, 2017 | 7.8 | 23 | NO | NO |
CVE-2021-35521MEDIUM A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows remote authenticated attackers to achieve denial of services an | Jul 22, 2021 | 5.9 | 21 | NO | NO |
CVE-2023-33217HIGH
By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent
denial of service for the terminal. the only way to recover | Dec 15, 2023 | 7.5 | 20 | NO | NO |
CVE-2021-35520MEDIUM A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows physically proximate authenticated attackers to achieve code e | Jul 22, 2021 | 6.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by IDEMIA.
Media articles that mention a CVE ID that affects a product developed by IDEMIA — matched by CVE ID, not by vendor name.