CVE-2024-0454
Security Vulnerability on Match-on-Chip FPR Architecture
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 Jan 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor.
This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity.
Version which is lower than 3.0.12011.08009(Legacy)/3.3.12011.08103(ESS) would suffer this risk on DELL Inspiron platform.
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Affected products
ELAN · DELL InspironWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →