CVE-2024-23592
CVE-2024-23592 is an authentication bypass vulnerability affecting Lenovo devices using Synaptics fingerprint readers. This flaw allows an attacker with physical access to potentially replay fingerprints and circumvent Windows Hello authentication. With an SVRS of 30, while not critical, this vulnerability still presents a risk and should be monitored. The fingerprint reader vulnerability means unauthorized access could be gained if an attacker manages to capture and replay a valid fingerprint. Although the CVSS score is 0, the SVRS considers real-world exploitability from sources like dark web mentions and social media, indicating a potential risk that shouldn't be ignored. This is significant because it could compromise the security of Lenovo devices relying on fingerprint authentication, allowing unauthorized users to access sensitive data. Mitigation steps should be considered, especially in environments with elevated physical security risks.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.