MEDIUM · 6.0

CVE-2019-18618

Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacke...

Vulnerability Description

Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.

CVSS Score

6.0

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
SynapticsVfs75Xx Firmware5.1.5.51
SynapticsVfs75Xx-
LenovoThinkpad 25 Firmware< 5.2.3540.26
LenovoThinkpad 25-
LenovoThankpad A475 Firmware< 5.02.3539.0026
LenovoThankpad A475-
LenovoThankpad A485 Firmware< 5.03.3542.0026
LenovoThankpad A485-
LenovoThinkpad E480 Firmware< 5.2.321.26
LenovoThinkpad E480-
LenovoThinkpad E580 Firmware< 5.2.321.26
LenovoThinkpad E580-
LenovoThinkpad E485 Firmware< 5.2.321.26
LenovoThinkpad E485-
LenovoThinkpad E585 Firmware< 5.2.321.26
LenovoThinkpad E585-
LenovoThinkpad E490S Firmware< 5.2.321.26
LenovoThinkpad E490S-
LenovoThinkpad S3 Firmware< 5.2.321.26
LenovoThinkpad S3-

References

FAQ

What is CVE-2019-18618?

CVE-2019-18618 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacke...

How severe is CVE-2019-18618?

CVE-2019-18618 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-18618?

Check the references section above for vendor advisories and patch information. Affected products include: Synaptics Vfs75Xx Firmware, Synaptics Vfs75Xx, Lenovo Thinkpad 25 Firmware, Lenovo Thinkpad 25, Lenovo Thankpad A475 Firmware.