Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.
Link | Tags |
---|---|
https://www.synaptics.com/company/blog/ | vendor advisory |
https://support.lenovo.com/us/en/product_security/LEN-31372 | third party advisory patch |
https://www.synaptics.com/sites/default/files/fingerprint-sensor-VFS7500-security-brief-2020-07-14.pdf | vendor advisory |
https://support.hp.com/us-en/document/c06696474 | third party advisory patch |