CVE-2025-13455

7.8

Lenovo · ThinkPlus Configuration Software

A local authentication bypass vulnerability in Lenovo ThinkPlus configuration software allows an authenticated user to enroll an untrusted fingerprint on affected devices.

Executive summary

A local authentication bypass vulnerability in Lenovo ThinkPlus configuration software allows an authenticated user to enroll unauthorized fingerprints, posing a significant risk to device security.

Vulnerability

This is an authentication bypass flaw (CWE-290) occurring within the configuration software. It allows an already authenticated local user to manipulate the device authentication mechanism and register an unauthorized fingerprint.

Business impact

The ability to enroll an unauthorized fingerprint grants a malicious actor persistent, physical access to the protected device. Given the CVSS score of 7.8, this vulnerability represents a high risk to data confidentiality and integrity, as it facilitates unauthorized access to sensitive information stored on or accessed via these devices.

Remediation

Immediate Action: Review the official Lenovo security advisory at https://iknow.lenovo.com.cn/detail/436983 and follow the specific product impact guidance provided by the vendor.

Proactive Monitoring: Monitor system logs for unauthorized configuration changes or attempts to access the fingerprint enrollment utility by non-administrative users.

Compensating Controls: Restrict local user privileges on systems utilizing these devices to ensure that only authorized personnel can execute configuration software.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

While this vulnerability requires local access, the potential for persistent unauthorized biometric access makes it a significant security concern for enterprise environments. Administrators should consult the linked Lenovo advisory immediately to determine if a firmware or software update is available for their specific device version and apply the recommended mitigations to prevent unauthorized fingerprint enrollment.

More Lenovo CVEs

Sources

Originally found and disclosed by Lenovo thanks Xusheng Li (Vector 35 Inc) for reporting these issues., per the CVE Program record.