7.8

CVE-2022-1892

A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

Data is provided by the National Vulnerability Database (NVD)
Lenovo100e 2nd Gen Firmware Version < frcn23ww
   Lenovo100e 2nd Gen Version-
Lenovo100w Gen 3 Firmware Version < gacn38ww
   Lenovo100w Gen 3 Version-
Lenovo13w Yoga Firmware Version < jacn31ww
   Lenovo13w Yoga Version-
Lenovo14w Gen 2 Firmware Version < h0cn21ww
   Lenovo14w Gen 2 Version-
Lenovo300e 2nd Gen Firmware Version < frcn23ww
   Lenovo300e 2nd Gen Version-
Lenovo300w Gen 3 Firmware Version < gacn38ww
   Lenovo300w Gen 3 Version-
Lenovo500w Gen 3 Firmware Version < g6cn40ww
   Lenovo500w Gen 3 Version-
Lenovo730s-13iml Firmware Version < brcn20ww
   Lenovo730s-13iml Version-
LenovoFlex 3-11ada05 Firmware Version < fpcn26ww
   LenovoFlex 3-11ada05 Version-
LenovoFlex 5-14alc05 Firmware Version < gjcn27ww
   LenovoFlex 5-14alc05 Version-
LenovoFlex 5-14are05 Firmware Version < eecn39ww
   LenovoFlex 5-14are05 Version-
LenovoFlex 5-14iil05 Firmware Version < eecn40ww
   LenovoFlex 5-14iil05 Version-
LenovoFlex 5-14itl05 Firmware Version < fxcn38ww
   LenovoFlex 5-14itl05 Version-
LenovoFlex 5-15alc05 Firmware Version < gjcn27ww
   LenovoFlex 5-15alc05 Version-
LenovoFlex 5-15iil05 Firmware Version < eccn40ww
   LenovoFlex 5-15iil05 Version-
LenovoFlex 5-15itl05 Firmware Version < fxcn38ww
   LenovoFlex 5-15itl05 Version-
LenovoIdeapad 1-11ada05 Firmware Version < fqcn26ww
   LenovoIdeapad 1-11ada05 Version-
LenovoIdeapad 1-11igl05 Firmware Version < dwcn24ww
   LenovoIdeapad 1-11igl05 Version-
LenovoIdeapad 1-14ada05 Firmware Version < fqcn26ww
   LenovoIdeapad 1-14ada05 Version-
LenovoIdeapad 1-14igl05 Firmware Version < dwcn24ww
   LenovoIdeapad 1-14igl05 Version-
LenovoIdeapad 3-15ada05 Firmware Version < e8cn36ww
   LenovoIdeapad 3-15ada05 Version-
LenovoIdeapad 3-14ada05 Firmware Version < e8cn36ww
   LenovoIdeapad 3-14ada05 Version-
LenovoIdeapad 3-14ada6 Firmware Version < hbcn24ww
   LenovoIdeapad 3-14ada6 Version-
LenovoIdeapad 3-14alc6 Firmware Version < glcn48ww
   LenovoIdeapad 3-14alc6 Version-
LenovoIdeapad 3-15ada6 Firmware Version < hbcn24ww
   LenovoIdeapad 3-15ada6 Version-
LenovoIdeapad 3-15alc6 Firmware Version < glcn48ww
   LenovoIdeapad 3-15alc6 Version-
LenovoIdeapad 3-17alc6 Firmware Version < e8cn36ww
   LenovoIdeapad 3-17alc6 Version-
LenovoIdeapad 3-17ada05 Firmware Version < hbcn24ww
   LenovoIdeapad 3-17ada05 Version-
LenovoIdeapad 3-17ada6 Firmware Version < glcn48ww
   LenovoIdeapad 3-17ada6 Version-
LenovoIdeapad 5 15aba7 Firmware Version < kacn14ww
   LenovoIdeapad 5 15aba7 Version-
LenovoIdeapad Flex 5 14alc7 Firmware Version < jccn29ww
   LenovoIdeapad Flex 5 14alc7 Version-
LenovoIdeapad Flex 5 16alc7 Firmware Version < jccn29ww
   LenovoIdeapad Flex 5 16alc7 Version-
LenovoLegion S7-15imh5 Firmware Version < hacn37ww
   LenovoLegion S7-15imh5 Version-
LenovoLegion S7-15ach6 Firmware Version < g1cn27ww
   LenovoLegion S7-15ach6 Version-
LenovoLegion S7-15arh5 Firmware Version < fdcn40ww
   LenovoLegion S7-15arh5 Version-
LenovoS145-14api Firmware Version < bucn33ww
   LenovoS145-14api Version-
LenovoS145-14ast Firmware Version < aycn28ww
   LenovoS145-14ast Version-
LenovoS145-15api Firmware Version < bucn33ww
   LenovoS145-15api Version-
LenovoS145-15ast Firmware Version < aycn28ww
   LenovoS145-15ast Version-
LenovoS540-13api Firmware Version < cxcn36ww
   LenovoS540-13api Version-
LenovoIdeapad S940-14iil Firmware Version < bqcn34ww
   LenovoIdeapad S940-14iil Version-
LenovoYoga S940-14iil Firmware Version < bqcn34ww
   LenovoYoga S940-14iil Version-
LenovoIdeapad Slim 1-14ast-05 Firmware Version < cwcn25ww
   LenovoIdeapad Slim 1-14ast-05 Version-
LenovoIdeapad Slim 1-11ast-05 Firmware Version < cwcn25ww
   LenovoIdeapad Slim 1-11ast-05 Version-
LenovoThinkbook 13s G3 Acn Firmware Version < gmcn29ww
   LenovoThinkbook 13s G3 Acn Version-
LenovoThinkbook 13s G2 Are Firmware Version < fvcn24ww
   LenovoThinkbook 13s G2 Are Version-
LenovoThinkbook 13s G2 Itl Firmware Version < f9cn50ww
   LenovoThinkbook 13s G2 Itl Version-
LenovoThinkbook 13s-iml Firmware Version < cqcn37ww
   LenovoThinkbook 13s-iml Version-
LenovoThinkbook 14-iil Firmware Version < djcn28ww
   LenovoThinkbook 14-iil Version-
LenovoThinkbook 14-iml Firmware Version < cjcn38ww
   LenovoThinkbook 14-iml Version-
LenovoThinkbook 14p G2 Ach Firmware Version < gwcn41ww
   LenovoThinkbook 14p G2 Ach Version-
LenovoThinkbook 14s G2 Itl Firmware Version < f9cn50ww
   LenovoThinkbook 14s G2 Itl Version-
LenovoThinkbook 14s-iml Firmware Version < cqcn37ww
   LenovoThinkbook 14s-iml Version-
LenovoThinkbook 15-iil Firmware Version < djcn28ww
   LenovoThinkbook 15-iil Version-
LenovoThinkbook 15-iml Firmware Version < cjcn38ww
   LenovoThinkbook 15-iml Version-
LenovoThinkbook 16p G2 Ach Firmware Version < gxcn42ww
   LenovoThinkbook 16p G2 Ach Version-
LenovoV130-15ikb Firmware Version < 8vcn31ww
   LenovoV130-15ikb Version-
LenovoV14 G2-alc Firmware Version < glcn48ww
   LenovoV14 G2-alc Version-
LenovoV14-ada Firmware Version < e8cn36ww
   LenovoV14-ada Version-
LenovoV15 G2-alc Firmware Version < glcn48ww
   LenovoV15 G2-alc Version-
LenovoV15-ada Firmware Version < e8cn36ww
   LenovoV15-ada Version-
LenovoYoga 9-15imh5 Firmware Version < epcn28ww
   LenovoYoga 9-15imh5 Version-
LenovoYoga C640-13iml Firmware Version < chcn28ww
   LenovoYoga C640-13iml Version-
LenovoYoga C640-13iml Lte Firmware Version < chcn28ww
   LenovoYoga C640-13iml Lte Version-
LenovoYoga C940-15irh Firmware Version < bscn37ww
   LenovoYoga C940-15irh Version-
LenovoYoga S730-13iml Firmware Version < brcn20ww
   LenovoYoga S730-13iml Version-
LenovoYoga S940-14iil Firmware Version < bqcn34ww
   LenovoYoga S940-14iil Version-
LenovoYoga Slim 7 Pro-14ach5 Firmware Version < gzcn29ww
   LenovoYoga Slim 7 Pro-14ach5 Version-
LenovoYoga Slim 7 Pro-14ach5 O Firmware Version < gzcn29ww
   LenovoYoga Slim 7 Pro-14ach5 O Version-
LenovoYoga Slim 7 Pro-14arh5 Firmware Version < gzcn24ww
   LenovoYoga Slim 7 Pro-14arh5 Version-
LenovoIdeapad 5-15alc05 Firmware Version < h2cn27ww
   LenovoIdeapad 5-15alc05 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.095
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().