ZeroHour

CVE-2019-18618

CVSS 3.1
6.0 medium
EPSS
<1%p44
Published
()
Modified
Description

Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.

Vendors
synapticslenovohp
Products
vfs75xx firmware, thinkpad 25 firmware, thankpad a475 firmware, thankpad a485 firmware, thinkpad e480 firmware, thinkpad e580 firmware, thinkpad e485 firmware, thinkpad e585 firmware, thinkpad e490s firmware, thinkpad s3 firmware, thinkpad e490 firmware, thinkpad e590 firmware
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.