PT-2018-1005 · Lenovo · Lenovo Fingerprint Manager

Publicado

2018-01-25

·

Atualizado

2019-05-08

·

CVE-2017-3762

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lenovo Fingerprint Manager Pro versions 8.01.86 and earlier
Description The issue concerns the storage of sensitive data, including users' Windows logon credentials and fingerprint data, which is encrypted using a weak algorithm and contains a hard-coded password. This data is accessible to all users with local non-administrative access to the system. The vulnerability allows a local attacker to gain access to user Windows credentials and fingerprint data.
Recommendations For Lenovo Fingerprint Manager Pro versions 8.01.86 and earlier, consider restricting local non-administrative access to the system until a patch is available. As a temporary workaround, restrict access to sensitive data stored by the Lenovo Fingerprint Manager Pro to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00223
CVE-2017-3762

Produtos afetados

Lenovo Fingerprint Manager