CVE Database · CVE-2024-23592
CVSS v3.1
6.3
EPSS
0.25%
Published
Apr 5, 2024
Modified
Apr 14, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication.
CVSS Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HWeaknesses (CWE)
References (2)