7.2

CVE-2022-1107

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LenovoThinkpad 11e Firmware Version < n15et78w
   LenovoThinkpad 11e Version-
LenovoThinkpad Helix Firmware Version < n17eta8w
   LenovoThinkpad Helix Version-
LenovoThinkpad L560 Firmware Version < n1het85w
   LenovoThinkpad L560 Version-
LenovoThinkpad L570 Firmware Version < n1xet65w
   LenovoThinkpad L570 Version-
LenovoThinkpad P50s Firmware Version < n1ket46w
   LenovoThinkpad P50s Version-
LenovoThinkpad P51s Firmware Version < n1vet50w
   LenovoThinkpad P51s Version-
LenovoThinkpad P52s Firmware Version < n27et36w
   LenovoThinkpad P52s Version-
LenovoThinkpad S540 Firmware Version < gpet80ww
   LenovoThinkpad S540 Version-
LenovoThinkpad T550 Firmware Version < n11et50w
   LenovoThinkpad T550 Version-
LenovoThinkpad T560 Firmware Version < n1ket46w
   LenovoThinkpad T560 Version-
LenovoThinkpad T570 Firmware Version < n1vet50w
   LenovoThinkpad T570 Version-
LenovoThinkpad T580 Firmware Version < n27et36w
   LenovoThinkpad T580 Version-
LenovoThinkpad X1 Tablet Gen 1 Firmware Version < n1let86w
   LenovoThinkpad X1 Tablet Gen 1 Version-
LenovoThinkpad X1 Tablet Gen 2 Firmware Version < n1oet50w
   LenovoThinkpad X1 Tablet Gen 2 Version-
LenovoThinkpad W540 Firmware Version < gnet92ww
   LenovoThinkpad W540 Version-
LenovoThinkpad W541 Firmware Version < gnet92ww
   LenovoThinkpad W541 Version-
LenovoThinkpad W550s Firmware Version < n11et50w
   LenovoThinkpad W550s Version-
LenovoThinkpad X1 Yoga Firmware Version < n1fet70w
   LenovoThinkpad X1 Yoga Version-
LenovoThinkpad X1 Yoga Gen 2 Firmware Version < n1net47w
   LenovoThinkpad X1 Yoga Gen 2 Version-
LenovoThinkpad X1 Yoga Gen 3 Firmware Version < n25et50w
   LenovoThinkpad X1 Yoga Gen 3 Version-
LenovoThinkpad X250 Firmware Version < n10et58w
   LenovoThinkpad X250 Version-
LenovoThinkpad X280 Firmware Version < n20et44w
   LenovoThinkpad X280 Version-
LenovoThinkpad X390 Firmware Version < n2let60w
   LenovoThinkpad X390 Version-
LenovoThinkpad 11e Yoga Firmware Version < n15et78w
   LenovoThinkpad 11e Yoga Version-
LenovoThinkpad Yoga 15 Firmware Version < n19et61w
   LenovoThinkpad Yoga 15 Version-
LenovoThinkpad Yoga 260 Firmware Version < n1get98w
   LenovoThinkpad Yoga 260 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.074
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.