CVE-2024-23592
An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.25%
- CWE
- CWE-358
- Published
- 2024-04-05
- Last modified
- 2026-03-13
Affected products
- Lenovo Synaptics Fingerprint Readers
Weakness type
Related vulnerabilities
- CVE-2026-46582 — A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
- CVE-2026-65058 — Trezor Safe improper security check in on-device display
- CVE-2026-49783 — Secure Boot Security Feature Bypass Vulnerability
- CVE-2026-54431 — Improper Data Validation in liboauth2
- CVE-2026-12577 — DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
- CVE-2026-48797 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
- CVE-2026-42081 — free5GC: UE Security Capability bypass on NGAP PathSwitchRequest
- CVE-2026-42082 — free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover