7.8
CVE-2022-48188
- EPSS 0.03%
- Veröffentlicht 05.06.2023 22:15:11
- Zuletzt bearbeitet 21.11.2024 07:32:56
- Quelle psirt@lenovo.com
- Teams Watchlist Login
- Unerledigt Login
A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Ideacentre Aio 3 21itl7 Firmware Version < o5akt33
Lenovo ≫ Ideacentre Aio 3-22itl6 Firmware Version < o5akt33
Lenovo ≫ Ideacentre Aio 3-24itl6 Firmware Version < o5akt33
Lenovo ≫ Ideacentre Aio 3-27itl6 Firmware Version < o5akt33
Lenovo ≫ Thinkcentre M720e Firmware Version < m1zkt40a
Lenovo ≫ Thinkcentre M720q Firmware Version < m1ukt70a
Lenovo ≫ Thinkcentre M720s Firmware Version < m1ukt70a
Lenovo ≫ Thinkcentre M720t Firmware Version < m1ukt70a
Lenovo ≫ Thinkcentre M725s Firmware Version < m25kt63a
Lenovo ≫ Thinkcentre M75s Gen 2 Firmware Version < m46kt30a
Lenovo ≫ Thinkcentre M75s Gen 2 Firmware Version < m3bkt30a
Lenovo ≫ Thinkcentre M75t Gen 2 Firmware Version < m46kt30a
Lenovo ≫ Thinkcentre M75t Gen 2 Firmware Version < m3akt4ca
Lenovo ≫ Thinkcentre M920q Firmware Version < m1ukt70a
Lenovo ≫ Thinkcentre M920s Firmware Version < m1ukt70a
Lenovo ≫ Thinkcentre M920t Firmware Version < m1ukt70a
Lenovo ≫ Thinkcentre M920x Firmware Version < m1ukt70a
Lenovo ≫ Thinkcentre M920z Firmware Version < m1mkt55a
Lenovo ≫ Ideacentre 510s-07icb Firmware Version < m22kt48a
Lenovo ≫ Ideacentre 510s-07icb Firmware Version < m22kt49a
Lenovo ≫ Ideacentre 510s-07ick Firmware Version < m30kt28a
Lenovo ≫ Ideacentre 510s-07ick Firmware Version < m1zkt40a
Lenovo ≫ Ideacentre 720-18apr Firmware Version < m25kt63a
Lenovo ≫ V30a-22itl Firmware Version < o5akt33
Lenovo ≫ V30a-24itl Firmware Version < o5akt33
Lenovo ≫ V530s-07icb Firmware Version < m22kt49a
Lenovo ≫ V530s-07icr Firmware Version < m1zkt40a
Lenovo ≫ Thinkstation P330 Tiny Firmware Version < m1ukt70a
Lenovo ≫ Thinkstation P360 Ultra Firmware Version < s0fkt27a
Lenovo ≫ Thinkstation P520 Firmware Version < s03kt58a
Lenovo ≫ Thinkstation P520c Firmware Version < s03kt58a
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.058 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
psirt@lenovo.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.