CVE-2024-0454 describes a design flaw in the ELAN Match-on-Chip FPR solution, affecting versions lower than 3.0.12011.08009 (Legacy) and 3.3.12011.08103 (ESS) on DELL Inspiron platforms. This vulnerability allows for the leakage and enumeration of valid SIDs using a spoofed sensor, enabling a bypass of Windows Hello recognition by cloning the SID and compromising account identity. Rated with a CVSS score of 6.1 (Medium), the vulnerability has a physical attack vector (AV:P) and low attack complexity (AC:L), leading to high confidentiality (C:H) and integrity (I:H) impacts. There is no user interaction required (UI:N), and the scope is unchanged (S:U). Currently, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, indicating low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.12011.08009CPE matchmatch criteria | cpe:2.3:o:emc:elan_match-on-chip_fpr_solution_firmware:3.0.12011.08009:*:*:*:*:*:*:* | ||
3.3.12011.08103CPE matchmatch criteria | cpe:2.3:o:emc:elan_match-on-chip_fpr_solution_firmware:3.3.12011.08103:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.