CVE-2019-18618
high-risk
Published 2020-07-22
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.
Do I need to act?
-
0.37% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.0/10
Medium
LOCAL
/ LOW complexity
Affected Products (20)
Elitebook 846 G5 Healthcare Edition Firmware
Elitebook 846 G6 Firmware
Elitebook 846 G6 Healthcare Edition Firmware
References (8)
Vendor Advisory
https://www.synaptics.com/company/blog/
Vendor Advisory
https://www.synaptics.com/company/blog/
54
/ 100
high-risk
Severity
20/34 · Moderate
Exploitability
1/34 · Minimal
Exposure
33/34 · Critical