CVE-2019-18618

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/07/2020
Last modified:
30/07/2020

Description

Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:synaptics:vfs75xx_firmware:5.1.5.51:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.1.337.26:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.1.3507.26:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.320.26:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.524.26:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.3109.26:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.3530.26:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.5024.26:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.3.3541.26:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.4.1116:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.8.1092:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.10.1100:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.10.1106:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.17.1099:*:*:*:*:*:*:*
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.17.1102:*:*:*:*:*:*:*