CVE-2024-23592 is an authentication bypass vulnerability affecting Lenovo devices equipped with Synaptics fingerprint readers. An attacker with physical access can replay fingerprints to bypass Windows Hello authentication, leading to high confidentiality, integrity, and availability impacts. This vulnerability has a CVSS score of 6.3 (Medium) due to its physical access requirement and high attack complexity. Currently, there is no public exploit code available, and it has not been observed in active exploitation, nor has it garnered significant community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Lenovo | Synaptics Fingerprint Readers | VariousCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.