Vulnerability Description
The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configuration packet to select the Windows template database, which allows bypass of Windows Hello authentication by enrolling an attacker's fingerprint.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Goodix | Fingerprint Sensor Firmware | - |
| Goodix | Fingerprint Sensor | - |
Related Weaknesses (CWE)
References
- https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/ExploitTechnical DescriptionThird Party Advisory
- https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2023-50430?
CVE-2023-50430 is a vulnerability with a CVSS score of 6.4 (MEDIUM). The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configura...
How severe is CVE-2023-50430?
CVE-2023-50430 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-50430?
Check the references section above for vendor advisories and patch information. Affected products include: Goodix Fingerprint Sensor Firmware, Goodix Fingerprint Sensor.