PT-2024-24189 · Bitdefender · Bitdefender Mobile Security

CVE-2024-31684

·

Published

2024-06-03

·

Updated

2024-11-12

CVSS v3.1

3.5

Low

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bitdefender Mobile Security version 4.11.3-gms
Description The issue is related to incorrect access control in the fingerprint authentication mechanism, allowing attackers to bypass fingerprint authentication due to the use of a deprecated API.
Recommendations For Bitdefender Mobile Security version 4.11.3-gms, consider disabling the fingerprint authentication mechanism until a patch is available. Restrict access to sensitive features that rely on fingerprint authentication to minimize the risk of exploitation.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-31684

Affected Products

Bitdefender Mobile Security