← Back

CVE-2024-0454

nvd nist
Published: Jan 12, 2024Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 0.9 / Impact: 5.2
Source: NVD

Description

ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity. Version which is lower than 3.0.12011.08009(Legacy)/3.3.12011.08103(ESS) would suffer this risk on DELL Inspiron platform.

Affected (2)

1 product
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Emc
Version 3.0.12011.08009
Version 3.3.12011.08103
Running on/withPlatform Versions
Emc
Elan Match On Chip Fpr Solution
All versions

References (3)

Source: 36106deb-8e95-420b-a0a0-e70af5d245df
Not Applicable
Source: nvd@nist.gov
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable

Timeline

No history available yet.