6.7

CVE-2022-4574

An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.  

Data is provided by the National Vulnerability Database (NVD)
LenovoThinkpad X13 Gen 3 Firmware Version < 1.33
   LenovoThinkpad X13 Gen 3 Version-
LenovoThinkpad X13 Gen 2 Firmware Version < 1.51
   LenovoThinkpad X13 Gen 2 Version-
LenovoThinkpad X13 Firmware Version < 1.26
   LenovoThinkpad X13 Version-
LenovoThinkpad X1 Titanium Firmware Version < 1.24
   LenovoThinkpad X1 Titanium Version-
LenovoThinkpad T16 Gen 1 Firmware Version < 1.31
   LenovoThinkpad T16 Gen 1 Version-
LenovoThinkpad T15p Gen 3 Firmware Version < 1.15
   LenovoThinkpad T15p Gen 3 Version-
LenovoThinkpad T15p Gen 2 Firmware Version < 1.19
   LenovoThinkpad T15p Gen 2 Version-
LenovoThinkpad T15p Gen 1 Firmware Version < 1.32
   LenovoThinkpad T15p Gen 1 Version-
LenovoThinkpad T15g Gen 2 Firmware Version < 1.25
   LenovoThinkpad T15g Gen 2 Version-
LenovoThinkpad T15g Gen 1 Firmware Version < 1.32
   LenovoThinkpad T15g Gen 1 Version-
LenovoThinkpad T14s Gen 3 Firmware Version < 1.33
   LenovoThinkpad T14s Gen 3 Version-
LenovoThinkpad T14s Gen 2 Firmware Version < 1.51
   LenovoThinkpad T14s Gen 2 Version-
LenovoThinkpad T14s Firmware Version < 1.26
   LenovoThinkpad T14s Version-
LenovoThinkpad T14 Gen 3 Firmware Version < 1.31
   LenovoThinkpad T14 Gen 3 Version-
LenovoThinkpad T14 Gen 1 Firmware Version < 1.28
   LenovoThinkpad T14 Gen 1 Version-
LenovoThinkpad P17 Gen 2 Firmware Version < 1.25
   LenovoThinkpad P17 Gen 2 Version-
LenovoThinkpad P17 Gen 1 Firmware Version < 1.32
   LenovoThinkpad P17 Gen 1 Version-
LenovoThinkpad P16s Gen 1 Firmware Version < 1.31
   LenovoThinkpad P16s Gen 1 Version-
LenovoThinkpad P16 Gen 1 Firmware Version < 1.17
   LenovoThinkpad P16 Gen 1 Version-
LenovoThinkpad P15v Gen 3 Firmware Version < 1.15
   LenovoThinkpad P15v Gen 3 Version-
LenovoThinkpad P15v Gen 2 Firmware Version < 1.19
   LenovoThinkpad P15v Gen 2 Version-
LenovoThinkpad P15v Gen 1 Firmware Version < 1.32
   LenovoThinkpad P15v Gen 1 Version-
LenovoThinkpad P15s Gen 1 Firmware Version < 1.28
   LenovoThinkpad P15s Gen 1 Version-
LenovoThinkpad P15 Gen 2 Firmware Version < 1.25
   LenovoThinkpad P15 Gen 2 Version-
LenovoThinkpad P15 Gen 1 Firmware Version < 1.32
   LenovoThinkpad P15 Gen 1 Version-
LenovoThinkpad P14s Gen 3 Firmware Version < 1.31
   LenovoThinkpad P14s Gen 3 Version-
LenovoThinkpad P14s Gen 1 Firmware Version < 1.28
   LenovoThinkpad P14s Gen 1 Version-
LenovoThinkpad P1 Gen 5 Firmware Version < 1.16
   LenovoThinkpad P1 Gen 5 Version-
LenovoThinkpad P1 Gen 4 Firmware Version1.22
   LenovoThinkpad P1 Gen 4 Version-
LenovoThinkpad P1 Gen 3 Firmware Version < 1.27
   LenovoThinkpad P1 Gen 3 Version-
LenovoThinkpad L15 Firmware Version < 1.20
   LenovoThinkpad L15 Version-
LenovoThinkpad L14 Firmware Version < 1.20
   LenovoThinkpad L14 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.034
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.