CVE-2024-23592: Lenovo Fingerprint Reader

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication.

Affected products

  • Lenovo Fingerprint Reader: any version
  • Lenovo Synaptics Fingerprint Readers

Published 2024-04-05. Last modified 2026-06-17.