CVE-2024-0454
Security Vulnerability on Match-on-Chip FPR Architecture
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
12 ene 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor.
This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity.
Version which is lower than 3.0.12011.08009(Legacy)/3.3.12011.08103(ESS) would suffer this risk on DELL Inspiron platform.
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Productos afectados
ELAN · DELL Inspiron¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →