6.7

CVE-2022-3430

A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Data is provided by the National Vulnerability Database (NVD)
LenovoD330-10igl Firmware Version < g0cn11ww
   LenovoD330-10igl Version-
LenovoIdeapad 5 Pro 16iah7 Firmware Version < j4cn33ww
   LenovoIdeapad 5 Pro 16iah7 Version-
LenovoIdeapad 5 Pro 16arh7 Firmware Version < j5cn27ww
   LenovoIdeapad 5 Pro 16arh7 Version-
LenovoIdeapad Duet 3 10igl5 Firmware Version < eqcn37ww
   LenovoIdeapad Duet 3 10igl5 Version-
LenovoSlim 7 16arh7 Firmware Version < klcn15ww
   LenovoSlim 7 16arh7 Version-
LenovoThinkbook 15p Imp Firmware Version < f6cn25ww
   LenovoThinkbook 15p Imp Version-
LenovoSlim 7-14are05 Firmware Version < dmcn43ww
   LenovoSlim 7-14are05 Version-
LenovoIdeapad Slim 7-14iil05 Firmware Version < dhcn35ww
   LenovoIdeapad Slim 7-14iil05 Version-
LenovoIdeapad Slim 7-14itl05 Firmware Version < fbcn29ww
   LenovoIdeapad Slim 7-14itl05 Version-
LenovoIdeapad Slim 7-15iil05 Firmware Version < dhcn35ww
   LenovoIdeapad Slim 7-15iil05 Version-
LenovoSlim 7-15imh05 Firmware Version < dncn32ww
   LenovoSlim 7-15imh05 Version-
LenovoSlim 7-15itl05 Firmware Version < fbcn29ww
   LenovoSlim 7-15itl05 Version-
LenovoThinkbook 13x Itg Firmware Version < hlcn30ww
   LenovoThinkbook 13x Itg Version-
LenovoThinkbook 14 G2 Are Firmware Version < facn33ww
   LenovoThinkbook 14 G2 Are Version-
LenovoThinkbook 14 G2 Itl Firmware Version < f8cn52ww
   LenovoThinkbook 14 G2 Itl Version-
LenovoThinkbook 14 G3 Acl Firmware Version < gqcn35ww_hfcn30ww
   LenovoThinkbook 14 G3 Acl Version-
LenovoThinkbook 14 G3 Itl Firmware Version < hrcn13ww
   LenovoThinkbook 14 G3 Itl Version-
LenovoThinkbook 14 G4+ Ara Firmware Version < j6cn40ww
   LenovoThinkbook 14 G4+ Ara Version-
LenovoThinkbook 14 G4+ Iap Firmware Version < hycn40ww
   LenovoThinkbook 14 G4+ Iap Version-
LenovoThinkbook 14p G3 Arh Firmware Version < k4cn31ww
   LenovoThinkbook 14p G3 Arh Version-
LenovoThinkbook 14s Yoga Itl Firmware Version < fncn40ww
   LenovoThinkbook 14s Yoga Itl Version-
LenovoThinkbook 15 G2 Are Firmware Version < facn33ww
   LenovoThinkbook 15 G2 Are Version-
LenovoThinkbook 15 G2 Itl Firmware Version < f8cn52ww
   LenovoThinkbook 15 G2 Itl Version-
LenovoThinkbook 15 G3 Acl Firmware Version < gqcn35ww_hfcn30ww
   LenovoThinkbook 15 G3 Acl Version-
LenovoThinkbook 15 G3 Itl Firmware Version < hrcn13ww
   LenovoThinkbook 15 G3 Itl Version-
LenovoThinkbook 15 Gd Aba Firmware Version < jpcn20ww
   LenovoThinkbook 15 G4 Aba Version-
LenovoThinkbook 15p G2 Ith Firmware Version < hjcn31ww
   LenovoThinkbook 15p G2 Ith Version-
LenovoThinkbook 16 G4+ Ara Firmware Version < j6cn40ww
   LenovoThinkbook 16 G4+ Ara Version-
LenovoThinkbook 16 G4+ Iap Firmware Version < hycn40ww
   LenovoThinkbook 16 G4+ Iap Version-
LenovoThinkbook 16p G3 Arh Firmware Version < kccn31ww
   LenovoThinkbook 16p G3 Arh Version-
LenovoThinkbook 16p Nx Arh Firmware Version < kjcn27ww
   LenovoThinkbook 16p Nx Arh Version-
LenovoThinkbook Plus G2 Itg Firmware Version < gycn31ww
   LenovoThinkbook Plus G2 Itg Version-
LenovoThinkbook Plus G3 Iap Firmware Version < k6cn29ww
   LenovoThinkbook Plus G3 Iap Version-
LenovoYoga Creator 7-15imh05 Firmware Version < dncn32ww
   LenovoYoga Creator 7-15imh05 Version-
LenovoYoga Duet 7-13iml05 Firmware Version < ercn30ww
   LenovoYoga Duet 7-13iml05 Version-
LenovoYoga Duet 7-13itl6 Firmware Version < gpcn24ww
   LenovoYoga Duet 7-13itl6 Version-
LenovoYoga Duet 7-13itl6-lte Firmware Version < gpcn24ww
   LenovoYoga Duet 7-13itl6-lte Version-
LenovoYoga Slim 7 Pro 16arh7 Firmware Version < klcn15ww
   LenovoYoga Slim 7 Pro 16arh7 Version-
LenovoYoga Slim 7-14are05 Firmware Version < dmcn43ww
   LenovoYoga Slim 7-14are05 Version-
LenovoYoga Slim 7-14iil05 Firmware Version < dmcn35ww
   LenovoYoga Slim 7-14iil05 Version-
LenovoYoga Slim 7-14itl05 Firmware Version < fbcn29ww
   LenovoYoga Slim 7-14itl05 Version-
LenovoYoga Slim 7-15iil05 Firmware Version < dhcn35ww
   LenovoYoga Slim 7-15iil05 Version-
LenovoYoga Slim 7-15imh05 Firmware Version < dncn32ww
   LenovoYoga Slim 7-15imh05 Version-
LenovoYoga Slim 7-15itl05 Firmware Version < fbcn29ww
   LenovoYoga Slim 7-15itl05 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.109
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.