ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor.
This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity.
Version which is lower than 3.0.12011.08009(Legacy)/3.3.12011.08103(ESS) would suffer this risk on DELL Inspiron platform.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-16249 ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity. Version which is lower than 3.0.12011.08009(Legacy)/3.3.12011.08103(ESS) would suffer this risk on DELL Inspiron platform.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 06 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Elan
Elan dell Inspiron
CPEs cpe:2.3:a:elan:dell_inspiron:*:*:*:*:*:*:*:*
Vendors & Products Elan
Elan dell Inspiron
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ELAN

Published:

Updated: 2024-11-06T17:10:10.844Z

Reserved: 2024-01-12T01:47:40.093Z

Link: CVE-2024-0454

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.725Z

cve-icon NVD

Status : Modified

Published: 2024-01-12T02:15:44.867

Modified: 2024-11-21T08:46:37.533

Link: CVE-2024-0454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.