PT-2024-24189 · Bitdefender · Bitdefender Mobile Security

Published

2024-06-03

·

Updated

2024-11-12

·

CVE-2024-31684

CVSS v3.1

3.5

Low

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bitdefender Mobile Security version 4.11.3-gms
Description The issue is related to incorrect access control in the fingerprint authentication mechanism, allowing attackers to bypass fingerprint authentication due to the use of a deprecated API.
Recommendations For Bitdefender Mobile Security version 4.11.3-gms, consider disabling the fingerprint authentication mechanism until a patch is available. Restrict access to sensitive features that rely on fingerprint authentication to minimize the risk of exploitation.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-31684

Affected Products

Bitdefender Mobile Security