Skip to main content

Hard-coded Password Lets Attackers Bypass Lenovo's Fingerprint Scanner




Lenovo has recently rolled out security patches for a severe vulnerability in its Fingerprint Manager Pro software that could allow leak sensitive data stored by the users.

Fingerprint Manager Pro is a utility for Microsoft Windows 7, 8 and 8.1 operating systems that allows users to log into their fingerprint-enabled Lenovo PCs using their fingers. The software could also be configured to store website credentials and authenticate site via fingerprint.
In addition to fingerprint data, the software also stores users sensitive information like their Windows login credentials—all of which are encrypted using a weak cryptography algorithm.



According to the company, Fingerprint Manager Pro version 8.01.86 and earlier contains a hard-coded password vulnerability, identified as CVE-2017-3762, that made the software accessible to all users with local non-administrative access.


"Sensitive data stored by Lenovo Fingerprint Manager Pro, including users’ Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system it is installed in," the company said in its advisory, giving brief about the vulnerability.


The vulnerability impacts Lenovo ThinkPad, ThinkCentre and ThinkStation laptops, and affects more than two dozen Lenovo ThinkPad models, five ThinkStation Models and eight ThinkCentre models that run Windows 7, 8 and the 8.1 operating systems.

Here's the full list of Lenovo devices compatible with Fingerprint Manager Pro and impacted by the vulnerability:
ThinkPad L560
ThinkPad P40 Yoga, P50s
ThinkPad T440, T440p, T440s, T450, T450s, T460, T540p, T550, T560
ThinkPad W540, W541, W550s
ThinkPad X1 Carbon (Type 20A7, 20A8), X1 Carbon (Type 20BS, 20BT)
ThinkPad X240, X240s, X250, X260
ThinkPad Yoga 14 (20FY), Yoga 460
ThinkCentre M73, M73z, M78, M79, M83, M93, M93p, M93z
ThinkStation E32, P300, P500, P700, P900
Lenovo has credited security researcher Jackson Thuraisamy with Security Compass for discovering and responsibly reporting the vulnerability.



The popular Chinese computer manufacturer strongly recommends its ThinkPad customers to update their devices to Fingerprint Manager Pro version 8.01.87 or later to address the issue. You can also head on to the company's official website to do so.

Since Microsoft added native fingerprint reader support with Windows 10 operating system, thus eliminating the need for the Fingerprint Manager Pro software, Lenovo laptops running Windows 10 are not impacted by the vulnerability.

Comments

Popular posts from this blog

#Facebook Video vs #YouTube Video find better one.

Live streams are now, mainstream. Live video has grown faster than most mediums, because it establishes a real-time connection and facilitates a conversation between the streamer and the audience. Nowadays, most social media platforms and video platforms allow you to stream live video. But, between the 2 major platforms, YouTube and Facebook, which one is actually the best for you to live stream to? On this blog post, we’ll talk about YouTube live vs. Facebook live. Here, you’ll find a side-by-side comparison between Facebook and YouTube, to help you decide where to focus your live streaming efforts as a brand or individual. Regardless of the platform, you prefer, keep in mind that they are the 2 biggest platforms out there. If you want to build an online audience, it’s wise to have an online presence on both. You can share different content on each of them, but for live streaming events and intricate live videos, you can and should go live on both platforms at the same time. This way,...

Thousands of Government Websites Hacked to Mine Cryptocurrencies

There was a time when hackers simply defaced websites to get attention, then they started hijacking them to spread banking trojan and ransomware, and now the trend has shifted towards injecting scripts into sites to mine cryptocurrencies. iPhone-X Styled ASUS Zenfone 5, Brings Along More Zenfone 5 Lite Renders Thousands of government websites around the world have been found infected with a specific script that secretly forces visitors' computers to mine cryptocurrency for attackers. Have you ever faced difficulty in transferring cash to a friend or relative The cryptocurrency mining script injection found on over 4,000 websites, including those belonging to UK's National Health Service (NHS), the Student Loan Company, and data protection watchdog Information Commissioner's Office (ICO), Queensland legislation, as well as the US government's court system. World’s tallest hotel Users who visited the hacked websites immediately had their computers...

CCI imposes Rs 135.86 crore penalty on Google for search bias

CCI noted in its order that undue intervention in product design can affect legitimate product improvements, given that design is an important dimension of competition. 4G smartphones at Rs 500, on a monthly plan of Rs 60 NEW DELHI|MUMBAI: The Competition Commission of India (CCI) has imposed a ?136-crore fine on Google for "search bias" and abusing its "dominant position". The Indian competition regulator's ruling comes after similar setbacks in the European Union and Russia for the world's most popular search engine. An introduction to Progressive Web Apps In a 190-page order, the Competition Commission of India (CCI) said Google abused its dominant position on three counts that largely relate to search, while no foul play was seen in case of advertising. CCI imposed a penalty amounting to 5% of the average revenue generated from India over the three years to FY15, an amount of ?135.85 crore, which has to be deposited within 60 days. A ma...