6.7
CVE-2022-3744
- EPSS 0.03%
- Veröffentlicht 23.08.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:20:09
- Quelle psirt@lenovo.com
- Teams Watchlist Login
- Unerledigt Login
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Ideapad 1 14iau7 Firmware Version < jkcn34ww
Lenovo ≫ Ideapad 1 14igl7 Firmware Version < kkcn15ww
Lenovo ≫ Ideapad 1 15iau7 Firmware Version < jkcn34ww
Lenovo ≫ Ideapad 1 15igl7 Firmware Version < kkcn15ww
Lenovo ≫ Ideapad 1-14ijl7 Firmware Version < htcn31ww
Lenovo ≫ Ideapad 1-15ijl7 Firmware Version < htcn31ww
Lenovo ≫ Ideapad 3 14iau7 Firmware Version < jkcn34ww
Lenovo ≫ Ideapad 3 15iau7 Firmware Version < jkcn34ww
Lenovo ≫ Ideapad 3 17iau7 Firmware Version < jkcn34ww
Lenovo ≫ Ideapad 3-15igl05 Firmware Version < dvcn28ww
Lenovo ≫ Ideapad 3-17iil05 Firmware Version < emcn56ww
Lenovo ≫ Ideapad 3-17itl6 Firmware Version < ggcn51ww
Lenovo ≫ Ideapad 5 15ial7 Firmware Version < jbcn27ww
Lenovo ≫ Ideapad 5-15itl05 Firmware Version < fhcn70ww
Lenovo ≫ L3-15iml05 Firmware Version < ejcn30ww
Lenovo ≫ L3-15itl6 Firmware Version < gfcn29ww
Lenovo ≫ Legion 5 15iah7 Firmware Version < j2cn49ww
Lenovo ≫ Legion 5 15iah7h Firmware Version < j2cn49ww
Lenovo ≫ Legion 5 Pro 16iah7 Firmware Version < j2cn49ww
Lenovo ≫ Legion 5 Pro 16iah7h Firmware Version < j2cn49ww
Lenovo ≫ Legion 5 Pro-16ith6 Firmware Version < h1cn52ww
Lenovo ≫ Legion 5 Pro-16ith6h Firmware Version < h1cn52ww
Lenovo ≫ Legion 5-15imh05 Firmware Version < efcn58ww
Lenovo ≫ Legion 5-15imh05h Firmware Version < efcn58ww
Lenovo ≫ Legion 5-15imh6 Firmware Version < g8cn22ww
Lenovo ≫ Legion 5-15ith6 Firmware Version < h1cn52ww
Lenovo ≫ Legion 5-15ith6h Firmware Version < h1cn52ww
Lenovo ≫ Legion 5-17imh05 Firmware Version < efcn58ww
Lenovo ≫ Legion 5-17imh05h Firmware Version < efcn58ww
Lenovo ≫ Legion 5-17ith6 Firmware Version < h1cn52ww
Lenovo ≫ Legion 5-17ith6h Firmware Version < h1cn52ww
Lenovo ≫ Legion 5p-15imh05 Firmware Version < efcn58ww
Lenovo ≫ Legion 5p-15imh05h Firmware Version < efcn58ww
Lenovo ≫ Legion 7 16iax7 Firmware Version < k1cn40ww
Lenovo ≫ Legion 7-16ithg6 Firmware Version < h1cn52ww
Lenovo ≫ S14 G2 Itl Firmware Version < ggcn51ww
Lenovo ≫ S14 G3 Iap Firmware Version < jkcn34ww
Lenovo ≫ Slim 7 14iap7 Firmware Version < jhcn28ww
Lenovo ≫ Slim 7 Carbon 13iap7 Firmware Version < k2cn34ww
Lenovo ≫ Slim 7 Prox 14iah7 Firmware Version < hmcn41ww
Lenovo ≫ Slim 9 14iap7 Firmware Version < j3cn49ww
Lenovo ≫ Thinkbook 15p Imh Firmware Version < f6cn26ww
Lenovo ≫ V14 G2 Ijl Firmware Version < htcn31ww
Lenovo ≫ V14 G3 Iap Firmware Version < jkcn34ww
Lenovo ≫ V15 G2 Ijl Firmware Version < htcn31ww
Lenovo ≫ V15 G3 Iap Firmware Version < jkcn34ww
Lenovo ≫ V17 G3 Iap Firmware Version < jkcn34ww
Lenovo ≫ S540-13itl Firmware Version < fzcn26ww
Lenovo ≫ Slim 7 Pro-14ihu5 Firmware Version < fjcn74ww
Lenovo ≫ Slim 9-14itl05 Firmware Version < escn56ww
Lenovo ≫ Thinkbook 15p G2 Ith Firmware Version < hjcn32ww
Lenovo ≫ V14 G1-iml Firmware Version < dxcn44ww
Lenovo ≫ V14 G2-itl Firmware Version < ggcn51ww
Lenovo ≫ V14-igl Firmware Version < dvcn28ww
Lenovo ≫ V15 G1-iml Firmware Version < dxcn44ww
Lenovo ≫ V15 G2-itl Firmware Version < ggcn51ww
Lenovo ≫ V15-igl Firmware Version < dvcn28ww
Lenovo ≫ V17 G2-itl Firmware Version < ggcn51ww
Lenovo ≫ V17-iil Firmware Version < emcn56ww
Lenovo ≫ Yoga 7 14ial7 Firmware Version < j1cn35ww
Lenovo ≫ Yoga 7 16iah7 Firmware Version < j1cn35ww
Lenovo ≫ Yoga 7 16iap7 Firmware Version < j1cn35ww
Lenovo ≫ Yoga 7-14itl5 Firmware Version < f5cn59ww
Lenovo ≫ Yoga 7-15itl5 Firmware Version < f5cn59ww
Lenovo ≫ Yoga 9 14iap7 Firmware Version < hncn42ww
Lenovo ≫ Yoga Slim 7 Carbon 13iap7 Firmware Version < k2cn34ww
Lenovo ≫ Yoga Slim 7 Pro 14iah7 Firmware Version < krcn14ww
Lenovo ≫ Yoga Slim 7 Pro 14iap7 Firmware Version < jhcn28ww
Lenovo ≫ Yoga Slim 7 Pro-14ihu5 Firmware Version < fjcn74ww
Lenovo ≫ Yoga Slim 7 Pro-14ihu5 O Firmware Version < fjcn74ww
Lenovo ≫ Yoga Slim 7 Pro-14itl5 Firmware Version < fjcn74ww
Lenovo ≫ Yoga Slim 7 Prox 14iah7 Firmware Version < hmcn41ww
Lenovo ≫ Yoga Slim 9 14iap7 Firmware Version < j3cn49ww
Lenovo ≫ Yoga Slim 9-14itl05 Firmware Version < escn56ww
Lenovo ≫ Ideapad 3-14igl05 Firmware Version < dvcn28ww
Lenovo ≫ Ideapad 3-14iil05 Firmware Version < emcn56ww
Lenovo ≫ Ideapad 3-14iml05 Firmware Version < dxcn44ww
Lenovo ≫ Ideapad 3-14itl05 Firmware Version < gccn32ww
Lenovo ≫ Ideapad 3-14itl6 Firmware Version < ggcn51ww
Lenovo ≫ Ideapad 3-15iil05 Firmware Version < emcn56ww
Lenovo ≫ Ideapad 3-15iml05 Firmware Version < dxcn44ww
Lenovo ≫ Ideapad 3-15itl05 Firmware Version < gccn32ww
Lenovo ≫ Ideapad 3-15itl6 Firmware Version < ggcn51ww
Lenovo ≫ Ideapad 3-17iml05 Firmware Version < dxcn44ww
Lenovo ≫ Ideapad 5-15iil05 Firmware Version < dpcn58ww
Lenovo ≫ Ideapad Creator 5-15imh05 Firmware Version < egcn40ww
Lenovo ≫ Ideapad Gaming 3-15imh05 Firmware Version < egcn40ww
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.04 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
psirt@lenovo.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.