QID 375625

Date Published: 2021-07-21

QID 375625: Lenovo Synaptics Fingerprint Multiple Vulnerabilities (LEN-31372)

Synaptics reported the following vulnerabilities in Synaptics Fingerprint drivers:

CVE-2019-18618: A vulnerability has been identified in some Synaptics Fingerprint drivers which could allow an attacker with physical or administrator access to modify data in the fingerprint sensors flash memory (only after clearing existing data).

CVE-2019-18619: A vulnerability has been identified in Synaptics Fingerprint drivers using Intel SGX that could allow execution of code within the SGX enclave.

Affected Products:
ThinkPad 25,A475,A485, ThinkPad E14 / R14 / S3 Gen 2,E480/E580,E485/E585,E490s/ThinkPad S3/ ThinkPad E490/E590/R490/R590, E570p / ThinkPad S5, ThinkPad L380 / S3 3rd Gen,L380 Yoga / S2 Yoga 3rd Gen,L390 / ThinkPad L390 Yoga,L460,L470,L480/L580,L490,L590 ThinkPad P1,P1 Gen 2 / X1 Extreme 2nd,P43s,P50 QID Detection Logic
: This QID checks if Vulnerable versions of Synaptics Fingerprint driver installed on windows system.

Successful exploitation could allow execution of code within the SGX enclave.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are recommended to update Synaptics Fingerprint driver . Refer to Lenovo support for bios updates.

    CVEs related to QID 375625

    Software Advisories
    Advisory ID Software Component Link
    LEN-31372 URL Logo support.lenovo.com/in/en/product_security/len-31372