PT-2020-12486 · Haemmerelectronics · Haemmerelectronics.Sepppenner.Windowshello
Sepppenner
·
Published
2020-04-14
·
Updated
2020-04-22
·
CVE-2020-11005
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HaemmerElectronics.SeppPenner.WindowsHello versions prior to 1.0.4
Description
The issue allows encrypted data to be potentially decrypted without needing authentication. If the library is used to encrypt text and write the output to a txt file, another executable could be able to decrypt the text using the static method
NCryptDecrypt from this same library without the need to use Windows Hello Authentication again.Recommendations
For versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the
NCryptDecrypt method to minimize the risk of exploitation.Fix
Authentication Bypass Using an Alternate Path or Channel
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Haemmerelectronics.Sepppenner.Windowshello