6.8

CVE-2022-48183

A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. 

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Thinkpad T14s Gen 3 Firmware Version < 1.30
   Lenovo ≫ Thinkpad T14s Gen 3 Version -
   Microsoft ≫ Windows Version -
Lenovo ≫ Thinkpad X13 Gen 3 Firmware Version < 1.30
   Lenovo ≫ Thinkpad X13 Gen 3 Version -
   Microsoft ≫ Windows Version -
Lenovo ≫ Thinkpad T14s Gen 3 Firmware Version < 1.35
   Lenovo ≫ Thinkpad T14s Gen 3 Version -
   Linux ≫ Linux Kernel Version -
Lenovo ≫ Thinkpad X13 Gen 3 Firmware Version < 1.35
   Lenovo ≫ Thinkpad X13 Gen 3 Version -
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.166
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Lenovo 6.1 0.9 5.2
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CWE-1263 Improper Physical Access Control

The product is designed with access restricted to certain information, but it does not sufficiently protect against an unauthorized actor with physical access to these areas.

https://support.lenovo.com/us/en/product_security/LEN-106014
Vendor Advisory