CVE-2024-31682

CRITICAL

Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.

Affects 0 products across 1 vendor.

BCS6.41
CVSS 3.19.8
EPSS0.5%
Percentile40th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-863: Incorrect Authorization

Software performs an authorization check incorrectly, allowing access beyond intended privileges.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.

BSID: BS-2024-GLOBAL-049086-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-31682?
A critical vulnerability in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.
What is the CVSS score for CVE-2024-31682?
CVE-2024-31682 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.5%.
Is CVE-2024-31682 actively exploited?
No confirmed active exploitation of CVE-2024-31682 as of 2026-05-30.
How do I remediate CVE-2024-31682?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-31682?
CVE-2024-31682 affects: Boost.
Vulnerability Details
CVE IDCVE-2024-31682
BSIDBS-2024-GLOBAL-049086-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2024-06-03
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from the application's use of a deprecated API for fingerprint authentication, which does not properly enforce access controls. An attacker could exploit this to gain unauthorized access to the application's features and data without valid fingerprint authentication.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Boost —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 782 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash4b51a650c14b3689121d5c86941360158316cc208c95fd9e4f6f6f72acd9d933ad1e6bb1438e5db4751a5bf1321808ba75bc199880a45ed9c44b940b5098523c
Related CVEs affecting Boost
CVE-2026-7637 9.8 The Boost plugin for WordPress is vulnerable to PHP Object Injection in versi... CVE-2024-45489 9.8 Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boos... CVE-2016-9840 8.8 Siemens CADRA CVE-2023-38297 8.4 An issue was discovered in a third-party com.factory.mmigroup component, ship... CVE-2026-7252 8.1 The WP-Optimize – Cache, Compress images, Minify & Clean database to boost pa...
View all Boost CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →