CVE-2024-23592
MEDIUMDescription
An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication.
Is your site exposed to CVE-2024-23592?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2024-23592? +
How severe is CVE-2024-23592? +
How do I check if I'm vulnerable to CVE-2024-23592? +
Related Vulnerabilities
In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. …
The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacker could …
DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / …
Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the …
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.