Sensitive Data Exposure in Lenovo Fingerprint Manager Pro
CVE-2017-3762
7.8HIGH
Key Information:
- Vendor
Lenovo
- Vendor
- CVE Published:
- 26 January 2018
What is CVE-2017-3762?
The Lenovo Fingerprint Manager Pro application stores sensitive user data, including Windows logon credentials and fingerprint information, with weak encryption methods. Notably, it employs a hard-coded password, which compromises the confidentiality of this data. Furthermore, malicious users with local non-administrative access can exploit this design flaw to retrieve sensitive information, posing significant security risks to affected systems.
Affected Version(s)
Lenovo Fingerprint Manager Pro Earlier than 8.01.87