The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via unspecified vectors. NOTE: the vendor disputes this because there is no command shell in the product or in the associated SDK
Link | Tags |
---|---|
https://gist.github.com/shiham101/4c49ece8ecac7c3c02ecbc6942aeca80 | third party advisory |