QID 375625

Date Published: 2021-07-21

QID 375625: Lenovo Synaptics Fingerprint Multiple Vulnerabilities (LEN-31372)

Synaptics reported the following vulnerabilities in Synaptics Fingerprint drivers:

CVE-2019-18618: A vulnerability has been identified in some Synaptics Fingerprint drivers which could allow an attacker with physical or administrator access to modify data in the fingerprint sensors flash memory (only after clearing existing data).

CVE-2019-18619: A vulnerability has been identified in Synaptics Fingerprint drivers using Intel SGX that could allow execution of code within the SGX enclave.

Affected Products:
ThinkPad 25,A475,A485, ThinkPad E14 / R14 / S3 Gen 2,E480/E580,E485/E585,E490s/ThinkPad S3/ ThinkPad E490/E590/R490/R590, E570p / ThinkPad S5, ThinkPad L380 / S3 3rd Gen,L380 Yoga / S2 Yoga 3rd Gen,L390 / ThinkPad L390 Yoga,L460,L470,L480/L580,L490,L590 ThinkPad P1,P1 Gen 2 / X1 Extreme 2nd,P43s,P50 QID Detection Logic
: This QID checks if Vulnerable versions of Synaptics Fingerprint driver installed on windows system.

Successful exploitation could allow execution of code within the SGX enclave.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are recommended to update Synaptics Fingerprint driver . Refer to Lenovo support for bios updates.

    CVEs related to QID 375625

    Software Advisories
    Advisory ID Software Component Link
    LEN-31372 URL Logo support.lenovo.com/in/en/product_security/len-31372
    © CVE.report 2026 |

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report