VulnerabilityModified
CVE-2024-0454
ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor.
MEDIUM 6.1EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity. Version which is lower than 3.0.12011.08009(Legacy)/3.3.12011.08103(ESS) would suffer this risk on DELL Inspiron platform.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-290
- Affected
- emc/elan match-on-chip fpr solution firmware
- Source
- 36106deb-8e95-420b-a0a0-e70af5d245df
References
- https://www.emc.com.tw/emc/tw/vulnerability-disclosure-policyNot Applicable
- https://github.com/advisories/GHSA-w3jx-33qh-77f8Third Party Advisory
- https://www.emc.com.tw/emc/tw/vulnerability-disclosure-policyNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.