Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is installed.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/102837 | vdb entry third party advisory |
https://support.lenovo.com/product_security/LEN-15999 | patch vendor advisory |
http://www.openwall.com/lists/oss-security/2019/05/08/4 | mailing list |
http://www.openwall.com/lists/oss-security/2019/05/08/3 | mailing list |
http://www.openwall.com/lists/oss-security/2019/05/08/5 | mailing list |