6
CVSSv3

CVE-2019-18618

Published: 22/07/2020 Updated: 30/07/2020
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6 | Impact Score: 5.2 | Exploitability Score: 0.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions before 2019-11-15) allows a local administrator or physical malicious user to compromise the confidentiality of sensor data via injection of an unverified partition table.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

synaptics vfs75xx firmware 5.1.5.51

synaptics vfs75xx firmware 5.1.337.26

synaptics vfs75xx firmware 5.1.3507.26

synaptics vfs75xx firmware 5.2.320.26

synaptics vfs75xx firmware 5.2.524.26

synaptics vfs75xx firmware 5.2.3109.26

synaptics vfs75xx firmware 5.2.3530.26

synaptics vfs75xx firmware 5.2.5024.26

synaptics vfs75xx firmware 5.3.3541.26

synaptics vfs75xx firmware 5.5.4.1116

synaptics vfs75xx firmware 5.5.8.1092

synaptics vfs75xx firmware 5.5.10.1100

synaptics vfs75xx firmware 5.5.10.1106

synaptics vfs75xx firmware 5.5.17.1099

synaptics vfs75xx firmware 5.5.17.1102

synaptics vfs75xx firmware 5.5.35.1058

synaptics vfs75xx firmware 5.5.502.79

synaptics vfs75xx firmware 5.5.512.1051

synaptics vfs75xx firmware 5.5.2734.1050

synaptics vfs75xx firmware 5.5.2810.1050

lenovo thinkpad 25 firmware

lenovo thankpad a475 firmware

lenovo thankpad a485 firmware

lenovo thinkpad e480 firmware

lenovo thinkpad e580 firmware

lenovo thinkpad e485 firmware

lenovo thinkpad e585 firmware

lenovo thinkpad e490s firmware

lenovo thinkpad s3 firmware

lenovo thinkpad e490 firmware

lenovo thinkpad e590 firmware

lenovo thinkpad r490 firmware

lenovo thinkpad r590 firmware

lenovo thinkpad l480 firmware

lenovo thinkpad l580 firmware

lenovo thinkpad p1 firmware

lenovo thinkpad p1 gen 2 firmware

lenovo thinkpad x1 extreme 2nd firmware

lenovo thinkpad p43s firmware

lenovo thinkpad p50 firmware

lenovo thinkpad p51 firmware

lenovo thinkpad p51s (20jx) firmware

lenovo thinkpad p51s (20kx) firmware

lenovo thinkpad p51s (20hx) firmware

lenovo thinkpad p52 firmware

lenovo thinkpad p52s firmware

lenovo thinkpad p53 firmware

lenovo thinkpad p53s firmware

lenovo thinkpad p70 firmware

lenovo thinkpad p71 (20hx) firmware

lenovo thinkpad p72 firmware

lenovo thinkpad p73 firmware

lenovo thinkpad t25 (20k7) firmware

lenovo thinkpad t460p firmware

lenovo thinkpad t460s firmware

lenovo thinkpad t470 (20hx) firmware

lenovo thinkpad t470 (20jx) firmware

lenovo thinkpad t470p firmware

lenovo thinkpad t470s (20hx) firmware

lenovo thinkpad t470s (20jx) firmware

lenovo thinkpad t480 firmware

lenovo thinkpad t480s firmware

lenovo thinkpad t490 firmware

lenovo thinkpad t490s firmware

lenovo thinkpad t570 (20hx) firmware

lenovo thinkpad t570(20jx) firmware

lenovo thinkpad t580 firmware

lenovo thinkpad t590 firmware

lenovo thinkpad x1 carbon (20hx) firmware

lenovo thinkpad x1 carbon (20kx) firmware

lenovo thinkpad x1 carbon firmware

lenovo thinkpad x1 yoga 4th gen firmware

lenovo thinkpad x1 extreme firmware

lenovo thinkpad x1 tablet firmware

lenovo thinkpad x1 tablet (20jx) firmware

lenovo thinkpad x1 yoga firmware

lenovo thinkpad x1 yoga (20jx) firmware

lenovo thinkpad x1 yoga 3rd gen firmware

lenovo thinkpad x270 firmware

lenovo thinkpad x280 firmware

lenovo thinkpad x380 yoga firmware

lenovo thinkpad x390 firmware

lenovo thinkpad x390 yoga firmware

lenovo thinkpad yoga 370 firmware

lenovo thinkpad s1 3rd firmware

lenovo thinkpad yoga 260 firmware

lenovo thinkpad yoga s1 firmware

lenovo thinkpad a275 firmware

hp elite x2 1012 g2 firmware

hp elite x2 1013 g3 firmware

hp elite x2 g4 firmware

hp elitebook 1040 g4 firmware

hp elitebook 1050 g1 firmware

hp elitebook 735 g5 firmware

hp elitebook 735 g6 firmware

hp elitebook 745 g5 firmware

hp elitebook 745 g6 firmware

hp elitebook 755 g5 firmware

hp elitebook 830 g5 firmware

hp elitebook 830 g6 firmware

hp elitebook 836 g5 firmware

hp elitebook 836 g6 firmware

hp elitebook 840 g5 firmware

hp elitebook 840 g5 healthcare edition firmware

hp elitebook 840 g6 firmware

hp elitebook 840 g6 healthcare edition firmware

hp elitebook 846 g5 firmware

hp elitebook 846 g5 healthcare edition firmware

hp elitebook 846 g6 firmware

hp elitebook 846 g6 healthcare edition firmware

hp elitebook 850 g5 firmware

hp elitebook 850 g6 firmware

hp elitebook x360 1020 g2 firmware

hp elitebook x360 1030 g2 firmware

hp elitebook x360 1030 g3 firmware

hp elitebook x360 1030 g4 firmware

hp elitebook x360 1040 g5 firmware

hp elitebook x360 1040 g6 firmware

hp elitebook x360 830 g5 firmware

hp elitebook x360 830 g6 firmware

hp pro x2 612 g2 firmware

hp probook 430 g6 firmware

hp probook 440 g6 firmware

hp probook 445 g6 firmware

hp probook 445r g6 firmware

hp probook 450 g6 firmware

hp probook 455 g6 firmware

hp probook 455r g6 firmware

hp probook 640 g5 firmware

hp probook 650 g5 firmware

hp zbook 14u g5 firmware

hp zbook 14u g6 firmware

hp zbook 15 g5 firmware

hp zbook 15 g6 firmware

hp zbook 15u g5 firmware

hp zbook 15u g6 firmware

hp zbook 17 g5 firmware

hp zbook 17 g6 firmware

hp zbook studio g5 firmware

hp zbook studio x360 g5 firmware

hp zhan 66 pro 13 g2 firmware

hp zhan 66 pro 14 g2 firmware

hp zhan 66 pro 15 g2 firmware

hp zhan x 13 g2 firmware

hp elite slice firmware

hp eliteone 1000 g1 firmware

hp eliteone 1000 g2 firmware

hp mt44 firmware

hp mt45 firmware

hp envy x360 firmware

hp pavilion x360 firmware

hp spectre x360 firmware

Vendor Advisories

Synaptics has notified HP of a potential security vulnerability in certain versions of VFS75xx Fingerprint Sensors equipped with external flash, which may allow a local administrator or physical attacker to compromise the confidentiality of the fingerprint sensor’s data The Synaptics Security Brief for this vulnerability can be found on the Syna ...
Synaptics has notified HP of a potential security vulnerability in certain versions of VFS75xx Fingerprint Sensors equipped with external flash, which may allow a local administrator or physical attacker to compromise the confidentiality of the fingerprint sensor’s data The Synaptics Security Brief for this vulnerability can be found on the Syna ...