6.7

CVE-2023-34419

A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

Data is provided by the National Vulnerability Database (NVD)
LenovoLegion 5 Pro 16iah7h Firmware Version < j2cn51ww
   LenovoLegion 5 Pro 16iah7h Version-
LenovoLegion 5 Pro 16iah7 Firmware Version < j2cn51ww
   LenovoLegion 5 Pro 16iah7 Version-
LenovoLegion 5 15arh7 Firmware Version-
   LenovoLegion 5 15arh7 Version-
LenovoLegion 5 15arh7h Firmware Version-
   LenovoLegion 5 15arh7h Version-
LenovoLegion 5 15iah7h Firmware Version < j2cn51ww
   LenovoLegion 5 15iah7h Version-
LenovoLegion 5 15iah7 Firmware Version < j2cn51ww
   LenovoLegion 5 15iah7 Version-
LenovoLegion 5-15ach6 Firmware Version-
   LenovoLegion 5-15ach6 Version-
LenovoLegion 5-15ach6a Firmware Version-
   LenovoLegion 5-15ach6a Version-
LenovoLegion 5-15ach6h Firmware Version-
   LenovoLegion 5-15ach6h Version-
LenovoLegion 5-15ith6 Firmware Version-
   LenovoLegion 5-15ith6 Version-
LenovoLegion 5-15ith6h Firmware Version-
   LenovoLegion 5-15ith6h Version-
LenovoLegion 5-17ach6 Firmware Version-
   LenovoLegion 5-17ach6 Version-
LenovoLegion 5-17ach6h Firmware Version-
   LenovoLegion 5-17ach6h Version-
LenovoLegion 5-17ith6 Firmware Version-
   LenovoLegion 5-17ith6 Version-
LenovoLegion 5-17ith6h Firmware Version-
   LenovoLegion 5-17ith6h Version-
LenovoLegion 7-16arha7 Firmware Version-
   LenovoLegion 7-16arha7 Version-
LenovoLegion 7-16achg6 Firmware Version-
   LenovoLegion 7-16achg6 Version-
LenovoLegion 7-16ithg6 Firmware Version-
   LenovoLegion 7-16ithg6 Version-
LenovoLegion Pro 5 16irx8 Firmware Version < kwcn37ww
   LenovoLegion Pro 5 16irx8 Version-
LenovoLegion Pro 7 16irx8 Firmware Version < kwcn37ww
   LenovoLegion Pro 7 16irx8 Version-
LenovoLegion Pro 7 16irx8h Firmware Version < kwcn37ww
   LenovoLegion Pro 7 16irx8h Version-
LenovoLegion S7 16arha7 Firmware Version-
   LenovoLegion S7 16arha7 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.102
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.