Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is installed.
2018-01-26T01:29:00.203
2024-11-21T03:26:05.500
Modified
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lenovo | fingerprint_manager_pro | ≤ 8.01.86 | Yes |
Operating System | microsoft | windows_7 | - | No |
Operating System | microsoft | windows_8 | - | No |
Operating System | microsoft | windows_8.1 | - | No |