6.7
CVE-2022-4575
- EPSS 0.01%
- Published 30.10.2023 15:15:40
- Last modified 21.11.2024 07:35:31
- Source psirt@lenovo.com
- Teams watchlist Login
- Open Login
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.
Data is provided by the National Vulnerability Database (NVD)
Lenovo ≫ Thinkpad 25 Firmware Version < 1.73
Lenovo ≫ Thinkpad L560 Firmware Version < 1.62
Lenovo ≫ Thinkpad P50 Firmware Version < 1.71
Lenovo ≫ Thinkpad P50s Firmware Version < 1.45
Lenovo ≫ Thinkpad P70 Firmware Version < 2.45
Lenovo ≫ Thinkpad T470 Firmware Version < 1.73
Lenovo ≫ Thinkpad T470s Firmware Version < 1.49
Lenovo ≫ Thinkpad T560 Firmware Version < 1.45
Lenovo ≫ Thinkpad X1 Carbon 4th Gen Firmware Version < 1.56
Lenovo ≫ Thinkpad X1 Yoga 1st Gen Firmware Version < 1.56
Lenovo ≫ Thinkpad X260 Firmware Version < 1.50
Lenovo ≫ Thinkpad X270 Firmware Version < 1.47
Lenovo ≫ Thinkpad Yoga 260 Firmware Version < 1.88
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.01% | 0.001 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
psirt@lenovo.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.