// For flags

CVE-2017-3762

 

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is installed.

Los datos sensibles almacenados por Lenovo Fingerprint Manager Pro, en su versión 8.01.86 y anteriores, incluyendo las credenciales de inicio de sesión en Windows y los datos de huella digital de los usuarios, se cifran mediante un algoritmo débil, contienen una contraseña embebida y son accesibles a todos los usuarios con acceso local no administrativo al sistema en el que está instalado.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-12-16 CVE Reserved
  • 2018-01-26 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-798: Use of Hard-coded Credentials
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Lenovo
Search vendor "Lenovo"
Fingerprint Manager Pro
Search vendor "Lenovo" for product "Fingerprint Manager Pro"
<= 8.01.86
Search vendor "Lenovo" for product "Fingerprint Manager Pro" and version " <= 8.01.86"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows 7
Search vendor "Microsoft" for product "Windows 7"
--
Safe
Lenovo
Search vendor "Lenovo"
Fingerprint Manager Pro
Search vendor "Lenovo" for product "Fingerprint Manager Pro"
<= 8.01.86
Search vendor "Lenovo" for product "Fingerprint Manager Pro" and version " <= 8.01.86"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows 8
Search vendor "Microsoft" for product "Windows 8"
--
Safe
Lenovo
Search vendor "Lenovo"
Fingerprint Manager Pro
Search vendor "Lenovo" for product "Fingerprint Manager Pro"
<= 8.01.86
Search vendor "Lenovo" for product "Fingerprint Manager Pro" and version " <= 8.01.86"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows 8.1
Search vendor "Microsoft" for product "Windows 8.1"
--
Safe