CVE-2023-33217: Idemia Morphowave Compact Firmware

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the terminal. the only way to recover the terminal is by sending back the terminal to the manufacturer

Affected products

  • Idemia Morphowave Compact Firmware: before 2.12.2 (fixed in 2.12.2)
  • Idemia Morphowave SP Firmware: before 1.2.7 (fixed in 1.2.7)
  • Idemia Morphowave XP Firmware: before 2.12.2 (fixed in 2.12.2)
  • Idemia Sigma Extreme Firmware: before 4.15.5 (fixed in 4.15.5)
  • Idemia Sigma Lite+ Firmware: before 4.15.5 (fixed in 4.15.5)
  • Idemia Sigma Lite Firmware: before 4.15.5 (fixed in 4.15.5)
  • Idemia Sigma Wide Firmware: before 4.15.5 (fixed in 4.15.5)
  • Idemia Visionpass Firmware: before 2.12.2 (fixed in 2.12.2)

Published 2023-12-15. Last modified 2026-06-17.