CVE-2021-26824

HIGH

DM FingerTool v1.19 - Authentication Bypass via Replay Attack

Title source: llm
STIX 2.1

Description

DM FingerTool v1.19 in the DM PD065 Secure USB is susceptible to improper authentication by a replay attack, allowing local attackers to bypass user authentication and access all features and data on the USB.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://sites.google.com/view/boss-lab

Scores

CVSS v3 7.1
EPSS 0.0042
EPSS Percentile 33.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-294
Status published
Products (1)
dm_fingertool_project/dm_fingertool 1.19
Published Jul 26, 2021
Tracked Since Feb 18, 2026