ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity. Version which is lower than 3.0.12011.08009(Legacy)/3.3.12011.08103(ESS) would suffer this risk on DELL Inspiron platform.
History

Wed, 06 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Elan
Elan dell Inspiron
CPEs cpe:2.3:a:elan:dell_inspiron:*:*:*:*:*:*:*:*
Vendors & Products Elan
Elan dell Inspiron
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ELAN

Published: 2024-01-12T01:48:47.887Z

Updated: 2024-11-06T17:10:10.844Z

Reserved: 2024-01-12T01:47:40.093Z

Link: CVE-2024-0454

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.725Z

cve-icon NVD

Status : Analyzed

Published: 2024-01-12T02:15:44.867

Modified: 2024-01-22T16:10:47.897

Link: CVE-2024-0454

cve-icon Redhat

No data.