CVE-2024-0454
Last modified
CVE-2024-0454 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity. Version which is lower than 3.0.12011.08009(Legacy)/3.3.12011.08103(ESS) would suffer this risk on DELL Inspiron platform.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity. Version which is lower than 3.0.12011.08009(Legacy)/3.3.12011.08103(ESS) would suffer this risk on DELL Inspiron platform.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Emc | Elan Match-On-Chip Fpr Solution Firmware | 3.0.12011.08009 |
| Emc | Elan Match-On-Chip Fpr Solution Firmware | 3.3.12011.08103 |
References
- https://github.com/advisories/GHSA-w3jx-33qh-77f8Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-0454?
How severe is CVE-2024-0454?
How do I fix CVE-2024-0454?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-0448The Elementor Addons by Livemesh plugin for WordPress is vul…5.4
- CVE-2024-0449The ArtiBot Free Chat Bot for WordPress WebSites plugin for …4.8
- CVE-2024-0450An issue was found in the CPython `zipfile` module affecting…6.2
- CVE-2024-0451The AI ChatBot plugin for WordPress is vulnerable to unautho…5
- CVE-2024-0452The AI ChatBot plugin for WordPress is vulnerable to unautho…7.7
- CVE-2024-0453The AI ChatBot plugin for WordPress is vulnerable to unautho…7.7
- CVE-2024-0455The inclusion of the web scraper for AnythingLLM means that …7.5
- CVE-2024-0456An authorization vulnerability exists in GitLab versions 14.…4.3
- CVE-2024-0459A vulnerability has been found in Blood Bank & Donor Managem…7.2
- CVE-2024-0460A vulnerability was found in code-projects Faculty Managemen…9.8
- CVE-2024-0461A vulnerability was found in code-projects Online Faculty Cl…9.8
- CVE-2024-0462A vulnerability was found in code-projects Online Faculty Cl…9.8
Are you affected by CVE-2024-0454?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
