6.8

CVE-2022-48183

A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. 

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LenovoThinkpad T14s Gen 3 Firmware Version < 1.30
   LenovoThinkpad T14s Gen 3 Version-
   MicrosoftWindows Version-
LenovoThinkpad X13 Gen 3 Firmware Version < 1.30
   LenovoThinkpad X13 Gen 3 Version-
   MicrosoftWindows Version-
LenovoThinkpad T14s Gen 3 Firmware Version < 1.35
   LenovoThinkpad T14s Gen 3 Version-
   LinuxLinux Kernel Version-
LenovoThinkpad X13 Gen 3 Firmware Version < 1.35
   LenovoThinkpad X13 Gen 3 Version-
   LinuxLinux Kernel Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.288
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 6.1 0.9 5.2
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CWE-1263 Improper Physical Access Control

The product is designed with access restricted to certain information, but it does not sufficiently protect against an unauthorized actor with physical access to these areas.