6.7
CVE-2022-3742
- EPSS 0.02%
- Veröffentlicht 23.08.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:20:09
- Quelle psirt@lenovo.com
- Teams Watchlist Login
- Unerledigt Login
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Ideapad 1 14iau7 Firmware Version < jkcn34ww
Lenovo ≫ Ideapad 1 14igl7 Firmware Version < kkcn15ww
Lenovo ≫ Ideapad 1 15iau7 Firmware Version < jkcn34ww
Lenovo ≫ Ideapad 1 15igl7 Firmware Version < kkcn15ww
Lenovo ≫ Ideapad 1-14ijl7 Firmware Version < htcn31ww
Lenovo ≫ Ideapad 1-15ijl7 Firmware Version < htcn31ww
Lenovo ≫ Ideapad 3 14iau7 Firmware Version < jkcn34ww
Lenovo ≫ Ideapad 3 15iau7 Firmware Version < jkcn34ww
Lenovo ≫ Ideapad 3 17iau7 Firmware Version < jkcn34ww
Lenovo ≫ Ideapad 3-15igl05 Firmware Version < dvcn28ww
Lenovo ≫ Ideapad 3-17iil05 Firmware Version < emcn56ww
Lenovo ≫ Ideapad 3-17itl6 Firmware Version < ggcn51ww
Lenovo ≫ Ideapad 5 15ial7 Firmware Version < jbcn27ww
Lenovo ≫ Ideapad 5-15itl05 Firmware Version < fhcn70ww
Lenovo ≫ L3-15iml05 Firmware Version < ejcn30ww
Lenovo ≫ L3-15itl6 Firmware Version < gfcn29ww
Lenovo ≫ Legion 5 15iah7 Firmware Version < j2cn49ww
Lenovo ≫ Legion 5 15iah7h Firmware Version < j2cn49ww
Lenovo ≫ Legion 5 Pro 16iah7 Firmware Version < j2cn49ww
Lenovo ≫ Legion 5 Pro 16iah7h Firmware Version < j2cn49ww
Lenovo ≫ Legion 5 Pro-16ith6 Firmware Version < h1cn52ww
Lenovo ≫ Legion 5 Pro-16ith6h Firmware Version < h1cn52ww
Lenovo ≫ Legion 5-15imh05 Firmware Version < efcn58ww
Lenovo ≫ Legion 5-15imh05h Firmware Version < efcn58ww
Lenovo ≫ Legion 5-15imh6 Firmware Version < g8cn22ww
Lenovo ≫ Legion 5-15ith6 Firmware Version < h1cn52ww
Lenovo ≫ Legion 5-15ith6h Firmware Version < h1cn52ww
Lenovo ≫ Legion 5-17imh05 Firmware Version < efcn58ww
Lenovo ≫ Legion 5-17imh05h Firmware Version < efcn58ww
Lenovo ≫ Legion 5-17ith6 Firmware Version < h1cn52ww
Lenovo ≫ Legion 5-17ith6h Firmware Version < h1cn52ww
Lenovo ≫ Legion 5p-15imh05 Firmware Version < efcn58ww
Lenovo ≫ Legion 5p-15imh05h Firmware Version < efcn58ww
Lenovo ≫ Legion 7 16iax7 Firmware Version < k1cn40ww
Lenovo ≫ Legion 7-16ithg6 Firmware Version < h1cn52ww
Lenovo ≫ S14 G2 Itl Firmware Version < ggcn51ww
Lenovo ≫ S14 G3 Iap Firmware Version < jkcn34ww
Lenovo ≫ Slim 7 14iap7 Firmware Version < jhcn28ww
Lenovo ≫ Slim 7 Carbon 13iap7 Firmware Version < k2cn34ww
Lenovo ≫ Slim 7 Prox 14iah7 Firmware Version < hmcn41ww
Lenovo ≫ Slim 9 14iap7 Firmware Version < j3cn49ww
Lenovo ≫ Thinkbook 15p Imh Firmware Version < f6cn26ww
Lenovo ≫ V14 G2 Ijl Firmware Version < htcn31ww
Lenovo ≫ V14 G3 Iap Firmware Version < jkcn34ww
Lenovo ≫ V15 G2 Ijl Firmware Version < htcn31ww
Lenovo ≫ V15 G3 Iap Firmware Version < jkcn34ww
Lenovo ≫ V17 G3 Iap Firmware Version < jkcn34ww
Lenovo ≫ S540-13itl Firmware Version < fzcn26ww
Lenovo ≫ Slim 7 Pro-14ihu5 Firmware Version < fjcn74ww
Lenovo ≫ Slim 9-14itl05 Firmware Version < escn56ww
Lenovo ≫ Thinkbook 15p G2 Ith Firmware Version < hjcn32ww
Lenovo ≫ V14 G1-iml Firmware Version < dxcn44ww
Lenovo ≫ V14 G2-itl Firmware Version < ggcn51ww
Lenovo ≫ V14-igl Firmware Version < dvcn28ww
Lenovo ≫ V15 G1-iml Firmware Version < dxcn44ww
Lenovo ≫ V15 G2-itl Firmware Version < ggcn51ww
Lenovo ≫ V15-igl Firmware Version < dvcn28ww
Lenovo ≫ V17 G2-itl Firmware Version < ggcn51ww
Lenovo ≫ V17-iil Firmware Version < emcn56ww
Lenovo ≫ Yoga 7 14ial7 Firmware Version < j1cn35ww
Lenovo ≫ Yoga 7 16iah7 Firmware Version < j1cn35ww
Lenovo ≫ Yoga 7 16iap7 Firmware Version < j1cn35ww
Lenovo ≫ Yoga 7-14itl5 Firmware Version < f5cn59ww
Lenovo ≫ Yoga 7-15itl5 Firmware Version < f5cn59ww
Lenovo ≫ Yoga 9 14iap7 Firmware Version < hncn42ww
Lenovo ≫ Yoga Slim 7 Carbon 13iap7 Firmware Version < k2cn34ww
Lenovo ≫ Yoga Slim 7 Pro 14iah7 Firmware Version < krcn14ww
Lenovo ≫ Yoga Slim 7 Pro 14iap7 Firmware Version < jhcn28ww
Lenovo ≫ Yoga Slim 7 Pro-14ihu5 Firmware Version < fjcn74ww
Lenovo ≫ Yoga Slim 7 Pro-14ihu5 O Firmware Version < fjcn74ww
Lenovo ≫ Yoga Slim 7 Pro-14itl5 Firmware Version < fjcn74ww
Lenovo ≫ Yoga Slim 7 Prox 14iah7 Firmware Version < hmcn41ww
Lenovo ≫ Yoga Slim 9 14iap7 Firmware Version < j3cn49ww
Lenovo ≫ Yoga Slim 9-14itl05 Firmware Version < escn56ww
Lenovo ≫ Ideapad 3-14igl05 Firmware Version < dvcn28ww
Lenovo ≫ Ideapad 3-14iil05 Firmware Version < emcn56ww
Lenovo ≫ Ideapad 3-14iml05 Firmware Version < dxcn44ww
Lenovo ≫ Ideapad 3-14itl05 Firmware Version < gccn32ww
Lenovo ≫ Ideapad 3-14itl6 Firmware Version < ggcn51ww
Lenovo ≫ Ideapad 3-15iil05 Firmware Version < emcn56ww
Lenovo ≫ Ideapad 3-15iml05 Firmware Version < dxcn44ww
Lenovo ≫ Ideapad 3-15itl05 Firmware Version < gccn32ww
Lenovo ≫ Ideapad 3-15itl6 Firmware Version < ggcn51ww
Lenovo ≫ Ideapad 3-17iml05 Firmware Version < dxcn44ww
Lenovo ≫ Ideapad 5-15iil05 Firmware Version < dpcn58ww
Lenovo ≫ Ideapad Creator 5-15imh05 Firmware Version < egcn40ww
Lenovo ≫ Ideapad Gaming 3-15imh05 Firmware Version < egcn40ww
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.031 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
psirt@lenovo.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.