7.8

CVE-2022-3431

A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Data is provided by the National Vulnerability Database (NVD)
LenovoIdeapad Creator 5-16ach6 Firmware Version < gscn34ww
   LenovoIdeapad Creator 5-16ach6 Version-
LenovoIdeapad 5 Pro-16ihu6 Firmware Version < grcn22ww
   LenovoIdeapad 5 Pro-16ihu6 Version-
LenovoIdeapad 5 Pro-16ach6 Firmware Version < gscn34ww
   LenovoIdeapad 5 Pro-16ach6 Version-
LenovoYoga Slim 7-13itl05 Firmware Version < f7cn39ww
   LenovoYoga Slim 7-13itl05 Version-
LenovoYoga Slim 7-13acn05 Firmware Version < ghcn28ww
   LenovoYoga Slim 7-13acn05 Version-
LenovoYoga Slim 7 Pro 16arh7 Firmware Version < klcn15ww
   LenovoYoga Slim 7 Pro 16arh7 Version-
LenovoYoga Slim 7 Pro 16ach6 Firmware Version < hucn16ww
   LenovoYoga Slim 7 Pro 16ach6 Version-
LenovoYoga Duet 7-13itl6-lte Firmware Version < gpcn24ww
   LenovoYoga Duet 7-13itl6-lte Version-
LenovoYoga Duet 7-13itl6 Firmware Version < gpcn24ww
   LenovoYoga Duet 7-13itl6 Version-
LenovoYoga Duet 7-13iml05 Firmware Version < ercn30ww
   LenovoYoga Duet 7-13iml05 Version-
LenovoThinkbook Plus G3 Iap Firmware Version < k6cn29ww
   LenovoThinkbook Plus G3 Iap Version-
LenovoThinkbook Plus G2 Itg Firmware Version < gycn31ww
   LenovoThinkbook Plus G2 Itg Version-
LenovoThinkbook 16p Nx Arh Firmware Version < kjcn27ww
   LenovoThinkbook 16p Nx Arh Version-
LenovoThinkbook 16 G4+ Iap Firmware Version < hycn40ww
   LenovoThinkbook 16 G4+ Iap Version-
LenovoThinkbook 16 G4+ Ara Firmware Version < j6cn40ww
   LenovoThinkbook 16 G4+ Ara Version-
LenovoThinkbook 14 G4+ Iap Firmware Version < hycn40ww
   LenovoThinkbook 14 G4+ Iap Version-
LenovoThinkbook 14 G4+ Ara Firmware Version < j6cn40ww
   LenovoThinkbook 14 G4+ Ara Version-
LenovoThinkbook 13x Itg Firmware Version < hlcn30ww
   LenovoThinkbook 13x Itg Version-
LenovoS540-15iml Firmware Version < cncn22ww
   LenovoS540-15iml Version-
LenovoSlim 7 16arh7 Firmware Version < klcn15ww
   LenovoSlim 7 16arh7 Version-
LenovoIdeapad Duet 3 10igl5 Firmware Version < eqcn37ww
   LenovoIdeapad Duet 3 10igl5 Version-
LenovoIdeapad 5 Pro 16arh7 Firmware Version < j4cn33ww
   LenovoIdeapad 5 Pro 16arh7 Version-
LenovoD330-10igl Firmware Version < g0cn11ww
   LenovoD330-10igl Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.086
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.