6.7

CVE-2022-48189

An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. 

Data is provided by the National Vulnerability Database (NVD)
LenovoThinkpad E14 Firmware Version < 1.23
   LenovoThinkpad E14 Version-
LenovoThinkpad E14 Gen 2 Firmware Version < 1.55
   LenovoThinkpad E14 Gen 2 Version-
LenovoThinkpad E14 Gen 4 Firmware Version < 1.18
   LenovoThinkpad E14 Gen 4 Version-
LenovoThinkpad E14 Gen 4 Firmware Version < 1.16
   LenovoThinkpad E14 Gen 4 Version-
LenovoThinkpad E15 Firmware Version < 1.23
   LenovoThinkpad E15 Version-
LenovoThinkpad E15 Gen 2 Firmware Version < 1.55
   LenovoThinkpad E15 Gen 2 Version-
LenovoThinkpad E15 Gen 4 Firmware Version < 1.18
   LenovoThinkpad E15 Gen 4 Version-
LenovoThinkpad E15 Gen 4 Firmware Version < 1.16
   LenovoThinkpad E15 Gen 4 Version-
LenovoThinkpad E490 Firmware Version < 1.34
   LenovoThinkpad E490 Version-
LenovoThinkpad E490s Firmware Version < 1.34
   LenovoThinkpad E490s Version-
LenovoThinkpad E590 Firmware Version < 1.34
   LenovoThinkpad E590 Version-
LenovoThinkpad L13 Gen 3 Firmware Version < 1.14
   LenovoThinkpad L13 Gen 3 Version-
LenovoThinkpad L14 Firmware Version < 1.2
   LenovoThinkpad L14 Version-
LenovoThinkpad L14 Firmware Version < 1.3
   LenovoThinkpad L14 Version-
LenovoThinkpad L14 Firmware Version-
   LenovoThinkpad L14 Version-
LenovoThinkpad L14 Firmware Version < 1.26
   LenovoThinkpad L14 Version-
LenovoThinkpad L15 Firmware Version < 1.2
   LenovoThinkpad L15 Version-
LenovoThinkpad L15 Firmware Version < 1.3
   LenovoThinkpad L15 Version-
LenovoThinkpad L15 Gen 3 Firmware Version < 1.26
   LenovoThinkpad L15 Gen 3 Version-
LenovoThinkpad L490 Firmware Version < 1.32
   LenovoThinkpad L490 Version-
LenovoThinkpad L590 Firmware Version < 1.32
   LenovoThinkpad L590 Version-
LenovoThinkpad P1 Gen 2 Firmware Version < 1.46
   LenovoThinkpad P1 Gen 2 Version-
LenovoThinkpad P1 Gen 3 Firmware Version < 1.27
   LenovoThinkpad P1 Gen 3 Version-
LenovoThinkpad P1 Gen 4 Firmware Version < 1.22
   LenovoThinkpad P1 Gen 4 Version-
LenovoThinkpad P1 Gen 5 Firmware Version < 1.16
   LenovoThinkpad P1 Gen 5 Version-
LenovoThinkpad P14s Gen 1 Firmware Version < 1.28
   LenovoThinkpad P14s Gen 1 Version-
LenovoThinkpad P14s Gen 2 Firmware Version < 1.34
   LenovoThinkpad P14s Gen 2 Version-
LenovoThinkpad P15 Gen 1 Firmware Version < 1.32
   LenovoThinkpad P15 Gen 1 Version-
LenovoThinkpad P15 Gen 2 Firmware Version < 1.25
   LenovoThinkpad P15 Gen 2 Version-
LenovoThinkpad P15s Gen 1 Firmware Version < 1.28
   LenovoThinkpad P15s Gen 1 Version-
LenovoThinkpad P15v Gen 1 Firmware Version < 1.32
   LenovoThinkpad P15v Gen 1 Version-
LenovoThinkpad P15v Gen 2 Firmware Version < 1.19
   LenovoThinkpad P15v Gen 2 Version-
LenovoThinkpad P15v Gen 3 Firmware Version < 1.15
   LenovoThinkpad P15v Gen 3 Version-
LenovoThinkpad P16 Gen 1 Firmware Version < 1.17
   LenovoThinkpad P16 Gen 1 Version-
LenovoThinkpad P17 Gen 1 Firmware Version < 1.32
   LenovoThinkpad P17 Gen 1 Version-
LenovoThinkpad P17 Gen 2 Firmware Version < 1.25
   LenovoThinkpad P17 Gen 2 Version-
LenovoThinkpad P43s Firmware Version-
   LenovoThinkpad P43s Version-
LenovoThinkpad P53 Firmware Version < 1.4
   LenovoThinkpad P53 Version-
LenovoThinkpad P53s Firmware Version-
   LenovoThinkpad P53s Version-
LenovoThinkpad P73 Firmware Version < 1.4
   LenovoThinkpad P73 Version-
LenovoThinkpad T14 Gen 1 Firmware Version < 1.28
   LenovoThinkpad T14 Gen 1 Version-
LenovoThinkpad T14 Gen 1 Firmware Version < 1.28
   LenovoThinkpad T14 Gen 1 Version-
LenovoThinkpad T14 Gen 2 Firmware Version < 1.34
   LenovoThinkpad T14 Gen 2 Version-
LenovoThinkpad T14s Firmware Version < 1.26
   LenovoThinkpad T14s Version-
LenovoThinkpad T14s Gen 2 Firmware Version < 1.51
   LenovoThinkpad T14s Gen 2 Version-
LenovoThinkpad T14s Gen 2 Firmware Version < 1.37
   LenovoThinkpad T14s Gen 2 Version-
LenovoThinkpad T14s Gen 3 Firmware Version < 1.33
   LenovoThinkpad T14s Gen 3 Version-
LenovoThinkpad T15 Firmware Version < 1.28
   LenovoThinkpad T15 Version-
LenovoThinkpad T15g Gen 1 Firmware Version < 1.32
   LenovoThinkpad T15g Gen 1 Version-
LenovoThinkpad T15g Gen 2 Firmware Version < 1.25
   LenovoThinkpad T15g Gen 2 Version-
LenovoThinkpad T15p Gen 1 Firmware Version < 1.32
   LenovoThinkpad T15p Gen 1 Version-
LenovoThinkpad T15p Gen 2 Firmware Version < 1.19
   LenovoThinkpad T15p Gen 2 Version-
LenovoThinkpad T15p Gen 3 Firmware Version < 1.15
   LenovoThinkpad T15p Gen 3 Version-
LenovoThinkpad T490 Firmware Version-
   LenovoThinkpad T490 Version-
LenovoThinkpad T490 Firmware Version-
   LenovoThinkpad T490 Version-
LenovoThinkpad T490 Firmware Version-
   LenovoThinkpad T490 Version-
LenovoThinkpad T490s Firmware Version-
   LenovoThinkpad T490s Version-
LenovoThinkpad T590 Firmware Version-
   LenovoThinkpad T590 Version-
LenovoThinkpad X1 Titanium Firmware Version < 1.24
   LenovoThinkpad X1 Titanium Version-
LenovoThinkpad X13 Firmware Version < 1.26
   LenovoThinkpad X13 Version-
LenovoThinkpad X13 Gen 2 Firmware Version < 1.51
   LenovoThinkpad X13 Gen 2 Version-
LenovoThinkpad X13 Gen 2 Firmware Version < 1.37
   LenovoThinkpad X13 Gen 2 Version-
LenovoThinkpad X13 Gen 3 Firmware Version < 1.33
   LenovoThinkpad X13 Gen 3 Version-
LenovoThinkpad X390 Firmware Version-
   LenovoThinkpad X390 Version-
LenovoThinkpad X390 Firmware Version-
   LenovoThinkpad X390 Version-
LenovoThinkpad X390 Yoga Firmware Version < 1.95
   LenovoThinkpad X390 Yoga Version-
LenovoThinkpad Z13 Gen 1 Firmware Version < 1.57
   LenovoThinkpad Z13 Gen 1 Version-
LenovoThinkpad Z16 Gen 1 Firmware Version < 1.57
   LenovoThinkpad Z16 Gen 1 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.057
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.