6.8
CVE-2022-48183
- EPSS 0.13%
- Veröffentlicht 09.10.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:32:56
- Quelle psirt@lenovo.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Thinkpad T14s Gen 3 Firmware Version < 1.30
Lenovo ≫ Thinkpad X13 Gen 3 Firmware Version < 1.30
Lenovo ≫ Thinkpad T14s Gen 3 Firmware Version < 1.35
Lenovo ≫ Thinkpad X13 Gen 3 Firmware Version < 1.35
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.13% | 0.288 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
psirt@lenovo.com | 6.1 | 0.9 | 5.2 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
|
CWE-1263 Improper Physical Access Control
The product is designed with access restricted to certain information, but it does not sufficiently protect against an unauthorized actor with physical access to these areas.