4.3

CVE-2022-34888

The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.

Data is provided by the National Vulnerability Database (NVD)
LenovoThinkagile Vx3331 Firmware Version < 1.80_afbt20n
   LenovoThinkagile Vx3331 Version-
LenovoThinkagile Hx1021 Firmware Version < 3.60_tei386m
   LenovoThinkagile Hx1021 Version-
LenovoThinkagile Hx1320 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx1320 Version-
LenovoThinkagile Hx1321 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx1321 Version-
LenovoThinkagile Hx1520-r Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx1520-r Version-
LenovoThinkagile Hx1521-r Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx1521-r Version-
LenovoThinkagile Hx2320-e Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx2320-e Version-
LenovoThinkagile Hx2321 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx2321 Version-
LenovoThinkagile Hx2720-e Firmware Version < 5.20_tei3c8m
   LenovoThinkagile Hx2720-e Version-
LenovoThinkagile Hx3320 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx3320 Version-
LenovoThinkagile Hx3321 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx3321 Version-
LenovoThinkagile Hx3375 Firmware Version < 4.10_d8bt38l
   LenovoThinkagile Hx3375 Version-
LenovoThinkagile Hx3376 Firmware Version < 4.10_d8bt38l
   LenovoThinkagile Hx3376 Version-
LenovoThinkagile Hx3520-g Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx3520-g Version-
LenovoThinkagile Hx3521-g Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx3521-g Version-
LenovoThinkagile Hx3720 Firmware Version < 5.20_tei3c8m
   LenovoThinkagile Hx3720 Version-
LenovoThinkagile Hx3721 Firmware Version < 5.20_tei3c8m
   LenovoThinkagile Hx3721 Version-
LenovoThinkagile Hx5520 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx5520 Version-
LenovoThinkagile Hx5520-c Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx5520-c Version-
LenovoThinkagile Hx5521 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx5521 Version-
LenovoThinkagile Hx5521-c Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx5521-c Version-
LenovoThinkagile Hx7520 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx7520 Version-
LenovoThinkagile Hx7521 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Hx7521 Version-
LenovoThinkagile Hx7820 Firmware Version < 2.50_psi346l
   LenovoThinkagile Hx7820 Version-
LenovoThinkagile Hx7821 Firmware Version < 2.50_psi346l
   LenovoThinkagile Hx7821 Version-
LenovoThinkagile Mx1020 Firmware Version <= 3.60_tei386m
   LenovoThinkagile Mx1020 Version-
LenovoThinkagile Mx3330-f Firmware Version < 1.80_afbt20n
   LenovoThinkagile Mx3330-f Version-
LenovoThinkagile Mx3330-h Firmware Version < 1.80_afbt20n
   LenovoThinkagile Mx3330-h Version-
LenovoThinkagile Mx3331-f Firmware Version < 1.80_afbt20n
   LenovoThinkagile Mx3331-f Version-
LenovoThinkagile Mx3331-h Firmware Version < 1.80_afbt20n
   LenovoThinkagile Mx3331-h Version-
LenovoThinkagile Mx3530 F Firmware Version < 1.80_afbt20n
   LenovoThinkagile Mx3530 F Version-
LenovoThinkagile Mx3530-h Firmware Version < 1.80_afbt20n
   LenovoThinkagile Mx3530-h Version-
LenovoThinkagile Mx3531-f Firmware Version < 1.80_afbt20n
   LenovoThinkagile Mx3531-f Version-
LenovoThinkagile Mx3531 H Firmware Version < 1.80_afbt20n
   LenovoThinkagile Mx3531 H Version-
LenovoThinkagile Mx1021 Firmware Version < 3.60_tei386m
   LenovoThinkagile Mx1021 Version-
LenovoThinkagile Vx 2u4n Firmware Version < 5.20_tei3c8m
   LenovoThinkagile Vx 2u4n Version-
LenovoThinkagile Vx 4u Firmware Version < 2.50_psi346l
   LenovoThinkagile Vx 4u Version-
LenovoThinkagile Vx1320 Firmware Version < 5.20_tei3c8m
   LenovoThinkagile Vx1320 Version-
LenovoThinkagile Vx2320 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Vx2320 Version-
LenovoThinkagile Vx2330 Firmware Version < 1.80_afbt20n
   LenovoThinkagile Vx2330 Version-
LenovoThinkagile Vx3320 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Vx3320 Version-
LenovoThinkagile Vx3330 Firmware Version < 1.80_afbt20n
   LenovoThinkagile Vx3330 Version-
LenovoThinkagile Vx3520-g Firmware Version < 8.40-cdi394n
   LenovoThinkagile Vx3520-g Version-
LenovoThinkagile Vx3530-g Firmware Version < 1.80_afbt20n
   LenovoThinkagile Vx3530-g Version-
LenovoThinkagile Vx3720 Firmware Version < 5.20_tei3c8m
   LenovoThinkagile Vx3720 Version-
LenovoThinkagile Vx5520 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Vx5520 Version-
LenovoThinkagile Vx5530 Firmware Version < 1.80_afbt20n
   LenovoThinkagile Vx5530 Version-
LenovoThinkagile Vx7320 N Firmware Version < 8.40-cdi394n
   LenovoThinkagile Vx7320 N Version-
LenovoThinkagile Vx7330 Firmware Version < 1.80_afbt20n
   LenovoThinkagile Vx7330 Version-
LenovoThinkagile Vx7520 Firmware Version < 8.40-cdi394n
   LenovoThinkagile Vx7520 Version-
LenovoThinkagile Vx7520 N Firmware Version < 8.40-cdi394n
   LenovoThinkagile Vx7520 N Version-
LenovoThinkagile Vx7530 Firmware Version < 1.80_afbt20n
   LenovoThinkagile Vx7530 Version-
LenovoThinkagile Vx7531 Firmware Version < 1.80_afbt20n
   LenovoThinkagile Vx7531 Version-
LenovoThinkagile Vx7820 Firmware Version < 2.50_psi346l
   LenovoThinkagile Vx7820 Version-
LenovoThinkedge Se450 Firmware Version < 1.10_usx304w
   LenovoThinkedge Se450 Version-
LenovoThinkstation P920 Firmware Version < 8.40-cdi394n
   LenovoThinkstation P920 Version-
LenovoThinksystem Sd530 Firmware Version < 5.20_tei3c8m
   LenovoThinksystem Sd530 Version-
LenovoThinksystem Sd630 V2 Firmware Version < 2.00_tgbt36o
   LenovoThinksystem Sd630 V2 Version-
LenovoThinksystem Sd650 Dwc Firmware Version < 5.20_tei3c8m
   LenovoThinksystem Sd650 Dwc Version-
LenovoThinksystem Sd650 V2 Firmware Version < 2.00_tgbt36o
   LenovoThinksystem Sd650 V2 Version-
LenovoThinksystem Sd650-n V2 Firmware Version < 2.00_tgbt36o
   LenovoThinksystem Sd650-n V2 Version-
LenovoThinksystem Se350 Firmware Version < 3.60_tei386m
   LenovoThinksystem Se350 Version-
LenovoThinksystem Sn550 Firmware Version < 5.20_tei3c8m
   LenovoThinksystem Sn550 Version-
LenovoThinksystem Sn550 V2 Firmware Version < 2.00_tgbt36o
   LenovoThinksystem Sn550 V2 Version-
LenovoThinksystem Sn850 Firmware Version < 5.20_tei3c8m
   LenovoThinksystem Sn850 Version-
LenovoThinksystem Sr150 Firmware Version < 5.20_tei3c8m
   LenovoThinksystem Sr150 Version-
LenovoThinksystem Sr158 Firmware Version < 5.20_tei3c8m
   LenovoThinksystem Sr158 Version-
LenovoThinksystem Sr250 Firmware Version < 5.20_tei3c8m
   LenovoThinksystem Sr250 Version-
LenovoThinksystem Sr250 V2 Firmware Version < 1.96_tgbt34x
   LenovoThinksystem Sr250 V2 Version-
LenovoThinksystem Sr258 Firmware Version < 5.20_tei3c8m
   LenovoThinksystem Sr258 Version-
LenovoThinksystem Sr258 V2 Firmware Version < 1.96_tgbt34x
   LenovoThinksystem Sr258 V2 Version-
LenovoThinksystem Sr530 Firmware Version < 8.40-cdi394n
   LenovoThinksystem Sr530 Version-
LenovoThinksystem Sr550 Firmware Version < 8.40-cdi394n
   LenovoThinksystem Sr550 Version-
LenovoThinksystem Sr570 Firmware Version < 8.40-cdi394n
   LenovoThinksystem Sr570 Version-
LenovoThinksystem Sr590 Firmware Version < 8.40-cdi394n
   LenovoThinksystem Sr590 Version-
LenovoThinksystem Sr630 Firmware Version < 8.40-cdi394n
   LenovoThinksystem Sr630 Version-
LenovoThinksystem Sr630 V2 Firmware Version < 1.80_afbt20n
   LenovoThinksystem Sr630 V2 Version-
LenovoThinksystem Sr645 Firmware Version < 4.10_d8bt38l
   LenovoThinksystem Sr645 Version-
LenovoThinksystem Sr650 Firmware Version < 8.40-cdi394n
   LenovoThinksystem Sr650 Version-
LenovoThinksystem Sr650 V2 Firmware Version < 1.80_afbt20n
   LenovoThinksystem Sr650 V2 Version-
LenovoThinksystem Sr665 Firmware Version < 4.10_d8bt38l
   LenovoThinksystem Sr665 Version-
LenovoThinksystem Sr670 Firmware Version < 3.60_tei386m
   LenovoThinksystem Sr670 Version-
LenovoThinksystem Sr670 V2 Firmware Version < 2.00_tgbt36o
   LenovoThinksystem Sr670 V2 Version-
LenovoThinksystem Sr850 Firmware Version < 5.20_tei3c8m
   LenovoThinksystem Sr850 Version-
LenovoThinksystem Sr850 V2 Firmware Version < 2.00_tgbt36o
   LenovoThinksystem Sr850 V2 Version-
LenovoThinksystem Sr850p Firmware Version < 3.60_tei386m
   LenovoThinksystem Sr850p Version-
LenovoThinksystem Sr860 Firmware Version < 5.20_tei3c8m
   LenovoThinksystem Sr860 Version-
LenovoThinksystem Sr860 V2 Firmware Version < 2.00_tgbt36o
   LenovoThinksystem Sr860 V2 Version-
LenovoThinksystem Sr950 Firmware Version < 2.50_psi346l
   LenovoThinksystem Sr950 Version-
LenovoThinksystem St250 Firmware Version < 5.20_tei3c8m
   LenovoThinksystem St250 Version-
LenovoThinksystem St250 V2 Firmware Version < 1.96_tgbt34x
   LenovoThinksystem St250 V2 Version-
LenovoThinksystem St258 Firmware Version < 5.20_tei3c8m
   LenovoThinksystem St258 Version-
LenovoThinksystem St258 V2 Firmware Version < 1.96_tgbt34x
   LenovoThinksystem St258 V2 Version-
LenovoThinksystem St550 Firmware Version < 8.40-cdi394n
   LenovoThinksystem St550 Version-
LenovoThinksystem St650 V2 Firmware Version < 2.00_tgbt36o
   LenovoThinksystem St650 V2 Version-
LenovoThinksystem St658 V2 Firmware Version < 2.00_tgbt36o
   LenovoThinksystem St658 V2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.205
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
psirt@lenovo.com 2.7 1.2 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
CWE-184 Incomplete List of Disallowed Inputs

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

CWE-697 Incorrect Comparison

The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.