PT-2020-12486 · Haemmerelectronics · Haemmerelectronics.Sepppenner.Windowshello

Sepppenner

·

Published

2020-04-14

·

Updated

2020-04-22

·

CVE-2020-11005

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HaemmerElectronics.SeppPenner.WindowsHello versions prior to 1.0.4
Description The issue allows encrypted data to be potentially decrypted without needing authentication. If the library is used to encrypt text and write the output to a txt file, another executable could be able to decrypt the text using the static method NCryptDecrypt from this same library without the need to use Windows Hello Authentication again.
Recommendations For versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the NCryptDecrypt method to minimize the risk of exploitation.

Fix

Authentication Bypass Using an Alternate Path or Channel

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11005
GHSA-WVPV-FFCV-R6CW

Affected Products

Haemmerelectronics.Sepppenner.Windowshello