CVE-2019-18618
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/07/2020
Last modified:
30/07/2020
Description
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.
Impact
Base Score 3.x
6.00
Severity 3.x
MEDIUM
Base Score 2.0
3.60
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:synaptics:vfs75xx_firmware:5.1.5.51:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.1.337.26:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.1.3507.26:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.320.26:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.524.26:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.3109.26:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.3530.26:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.5024.26:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.3.3541.26:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.4.1116:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.8.1092:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.10.1100:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.10.1106:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.17.1099:*:*:*:*:*:*:* | ||
cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.17.1102:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page