CVE-2024-31682
Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.
Affects 0 products across 1 vendor.
Software performs an authorization check incorrectly, allowing access beyond intended privileges.
A critical vulnerability in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.
BSID: BS-2024-GLOBAL-049086-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-31682?
What is the CVSS score for CVE-2024-31682?
Is CVE-2024-31682 actively exploited?
How do I remediate CVE-2024-31682?
What systems are affected by CVE-2024-31682?
| CVE ID | CVE-2024-31682 |
|---|---|
| BSID | BS-2024-GLOBAL-049086-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2024-06-03 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from the application's use of a deprecated API for fingerprint authentication, which does not properly enforce access controls. An attacker could exploit this to gain unauthorized access to the application's features and data without valid fingerprint authentication.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Boost | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 4b51a650c14b3689121d5c86941360158316cc208c95fd9e4f6f6f72acd9d933ad1e6bb1438e5db4751a5bf1321808ba75bc199880a45ed9c44b940b5098523c |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →