CVE-2019-18619
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/07/2020
Last modified:
30/07/2020
Description
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.225.26:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.318.26:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.524.26:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.2.3530.26:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.3.3539.26:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.3.1116:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.8.1096:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.10.1093:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.11.1106:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.15.1102:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.38.1058:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.2734.1050:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.5.2811.1050:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:5.6.23.1000:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synaptics:vfs75xx_firmware:6.0.14.1108:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://support.hp.com/hk-en/document/c06696568
- https://support.lenovo.com/us/en/product_security/LEN-31372
- https://www.synaptics.com/company/blog/
- https://www.synaptics.com/sites/default/files/fingerprint-driver-SGX-security-brief-2020-07-14.pdf
- https://www.syssec.wiwi.uni-due.de/en/research/research-projects/analysis-of-tee-software/



