Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-8345 Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:54:14.531Z

Reserved: 2019-10-29T00:00:00

Link: CVE-2019-18618

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-22T14:15:14.737

Modified: 2024-11-21T04:33:22.317

Link: CVE-2019-18618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.