CVE-2023-50430
The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configuration packet to select the Windows template database, which allows bypass of Windows Hello authentication by enrolling an attacker's fingerprint.
- Affected products
- Dell Inspiron 15, Goodix Fingerprint Device, Windows Shell
- Goodix Fingerprint Sensor Firmware
- All versions
- CVSS 3.1
- 6.4 MEDIUM
- EPSS
- 0.4% (34th percentile)
- Weakness
- CWE-287
- NVD status
- Modified
- Published
- 2023-12-09
CVE-2023-50430 at NVD
No indexed exploits for CVE-2023-50430 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-50430 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.