7.2

CVE-2018-9062

In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

Data is provided by the National Vulnerability Database (NVD)
LenovoE42-80 Firmware Version < 2wcn40ww
   LenovoE42-80 Version-
LenovoE42-80 Isk Firmware Version < 0zcn48ww
   LenovoE42-80 Isk Version-
LenovoE52-80 Firmware Version < 2wcn40ww
   LenovoE52-80 Version-
LenovoE52-80 Isk Firmware Version < 0zcn48ww
   LenovoE52-80 Isk Version-
LenovoMiix 720-12ikb Firmware Version < 3scn68ww
   LenovoMiix 720-12ikb Version-
LenovoV310-14ikb Firmware Version < 2wcn40ww
   LenovoV310-14ikb Version-
LenovoV310-14isk Firmware Version < 0zcn48ww
   LenovoV310-14isk Version-
LenovoV310-15ikb Firmware Version < 2wcn40ww
   LenovoV310-15ikb Version-
LenovoV310-15isk Firmware Version < 0zcn48ww
   LenovoV310-15isk Version-
LenovoV510-14ikb Firmware Version < 2wcn40ww
   LenovoV510-14ikb Version-
LenovoV510-15ikb Firmware Version < 2wcn40ww
   LenovoV510-15ikb Version-
LenovoThinkpad L380 Firmware Version < r0ret28w
   LenovoThinkpad L380 Version-
LenovoThinkpad E480 Firmware Version < r0pet47w
   LenovoThinkpad E480 Version-
LenovoThinkpad E580 Firmware Version < r0pet47w
   LenovoThinkpad E580 Version-
LenovoThinkpad L480 Firmware Version < r0qet47w
   LenovoThinkpad L480 Version-
LenovoThinkpad L580 Firmware Version < r0qet47w
   LenovoThinkpad L580 Version-
LenovoThinkpad P51 Firmware Version < n1uet71w
   LenovoThinkpad P51 Version-
LenovoThinkpad P51s Firmware Version < n1vet45w
   LenovoThinkpad P51s Version-
LenovoThinkpad P52 Firmware Version < n2cet28w
   LenovoThinkpad P52 Version-
LenovoThinkpad P52s Firmware Version < n27et27w
   LenovoThinkpad P52s Version-
LenovoThinkpad P71 Firmware Version < n1tet50w
   LenovoThinkpad P71 Version-
LenovoThinkpad P72 Firmware Version < n2cet28w
   LenovoThinkpad P72 Version-
LenovoThinkpad T25 Firmware Version < n1qet77w
   LenovoThinkpad T25 Version-
LenovoThinkpad T470 Firmware Version < n1qet77w
   LenovoThinkpad T470 Version-
LenovoThinkpad T470p Firmware Version < r0fet44w
   LenovoThinkpad T470p Version-
LenovoThinkpad T470s Firmware Version < n1wet49w
   LenovoThinkpad T470s Version-
LenovoThinkpad T480 Firmware Version < n24et41w
   LenovoThinkpad T480 Version-
LenovoThinkpad T480s Firmware Version < n22et48w
   LenovoThinkpad T480s Version-
LenovoThinkpad T570 Firmware Version < n1vet45w
   LenovoThinkpad T570 Version-
LenovoThinkpad T580 Firmware Version < n27et27w
   LenovoThinkpad T580 Version-
LenovoThinkpad X380 Yoga Firmware Version < r0set29w
   LenovoThinkpad X380 Yoga Version-
LenovoThinkpad Yoga 11e Firmware Version < r0vet23w
   LenovoThinkpad Yoga 11e Version-
LenovoThinkpad Yoga 370 Firmware Version < r0het48w
   LenovoThinkpad Yoga 370 Version-
LenovoThinkpad S1 Firmware Version < r0het48w
   LenovoThinkpad S1 Version-
LenovoThinkpad X1 Carbon Firmware Version < n1met49w
   Lenovo20hq Version-
   Lenovo20hr Version-
LenovoThinkpad X1 Carbon Firmware Version < n23et52w
   Lenovo20k3 Version-
   Lenovo20k4 Version-
LenovoThinkpad X1 Carbon Firmware Version < n1met49w
   Lenovo20kg Version-
   Lenovo20kh Version-
LenovoThinkpad X1 Tablet Firmware Version < n1oet45w
   Lenovo20jb Version-
   Lenovo20jc Version-
LenovoThinkpad X1 Tablet Firmware Version < n1zet69w
   Lenovo20kj Version-
   Lenovo20kk Version-
LenovoThinkpad X1 Yoga Firmware Version < n1net42w
   Lenovo20jd Version-
   Lenovo20je Version-
   Lenovo20jf Version-
   Lenovo20jg Version-
LenovoThinkpad X1 Yoga Firmware Version < n25et38w
   Lenovo20ld Version-
   Lenovo20le Version-
   Lenovo20lf Version-
   Lenovo20lg Version-
LenovoThinkpad X270 Firmware Version < r0iet53w
   Lenovo20hm Version-
   Lenovo20hn Version-
   Lenovo20k5 Version-
   Lenovo20k6 Version-
LenovoThinkpad X280 Firmware Version < n20et33w
   Lenovo20ke Version-
   Lenovo20kf Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.317
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.