CVE-2024-23592

MEDIUM

Lenovo Synaptics Fingerprint Readers - Authentication Bypass via Fingerprint Replay

Title source: llm
STIX 2.1

Description

An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication.

References (1)

Core 1

Scores

CVSS v3 6.3
EPSS 0.0025
EPSS Percentile 16.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-358
Status published
Products (1)
Lenovo/Synaptics Fingerprint Readers Various
Published Apr 05, 2024
Tracked Since Feb 18, 2026