Unrated severityNVD Advisory· Published Jul 22, 2020· Updated Aug 5, 2024
CVE-2019-18618
CVE-2019-18618
Description
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Synaptics/VFS75xx family fingerprint sensorsdescription
Patches
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
4- support.hp.com/us-en/document/c06696474mitrex_refsource_MISC
- support.lenovo.com/us/en/product_security/LEN-31372mitrex_refsource_MISC
- www.synaptics.com/company/blog/mitrex_refsource_MISC
- www.synaptics.com/sites/default/files/fingerprint-sensor-VFS7500-security-brief-2020-07-14.pdfmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.