6.7

CVE-2023-4028

A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo13w Yoga Firmware Version < jacn38ww
   Lenovo13w Yoga Version-
Lenovo13w Yoga Gen 2 Firmware Version < kbcn20ww
   Lenovo13w Yoga Gen 2 Version-
LenovoIdeapad 1-11ada05 Firmware Version < fqcn29ww
   LenovoIdeapad 1-11ada05 Version-
LenovoIdeapad 1-11igl05 Firmware Version < dwcn28ww
   LenovoIdeapad 1-11igl05 Version-
LenovoIdeapad 1-14ada05 Firmware Version < fqcn29ww
   LenovoIdeapad 1-14ada05 Version-
LenovoIdeapad 1-14igl05 Firmware Version < dwcn28ww
   LenovoIdeapad 1-14igl05 Version-
LenovoFlex 5-14alc05 Firmware Version < gjcn32ww
   LenovoFlex 5-14alc05 Version-
LenovoFlex 5-14are05 Firmware Version < eecn43ww
   LenovoFlex 5-14are05 Version-
LenovoFlex 5-14iil05 Firmware Version < eccn45ww
   LenovoFlex 5-14iil05 Version-
LenovoFlex 5-14itl05 Firmware Version < fxcn44ww
   LenovoFlex 5-14itl05 Version-
LenovoFlex 5-15alc05 Firmware Version < gjcn32ww
   LenovoFlex 5-15alc05 Version-
LenovoFlex 5-15iil05 Firmware Version < eccn45ww
   LenovoFlex 5-15iil05 Version-
LenovoFlex 5-15itl05 Firmware Version < fxcn44ww
   LenovoFlex 5-15itl05 Version-
LenovoIdeapad Flex 5 14abr8 Firmware Version < l7cn17ww
   LenovoIdeapad Flex 5 14abr8 Version-
LenovoIdeapad Flex 5 14alc7 Firmware Version < jccn35ww
   LenovoIdeapad Flex 5 14alc7 Version-
LenovoIdeapad Flex 5 14iau7 Firmware Version < j7cn44ww
   LenovoIdeapad Flex 5 14iau7 Version-
LenovoIdeapad Flex 5 14iru8 Firmware Version < l6cn20ww
   LenovoIdeapad Flex 5 14iru8 Version-
LenovoIdeapad Flex 5 16abr8 Firmware Version < l7cn17ww
   LenovoIdeapad Flex 5 16abr8 Version-
LenovoIdeapad Flex 5 16alc7 Firmware Version < jccn35ww
   LenovoIdeapad Flex 5 16alc7 Version-
LenovoIdeapad Flex 5 16iau7 Firmware Version < j7cn44ww
   LenovoIdeapad Flex 5 16iau7 Version-
LenovoIdeapad Flex 5 16iru8 Firmware Version < l6cn20ww
   LenovoIdeapad Flex 5 16iru8 Version-
LenovoFlex 7 14iru8 Firmware Version < l6cn20ww
   LenovoFlex 7 14iru8 Version-
LenovoThinkbook 13s G2 Are Firmware Version < fvcn28ww
   LenovoThinkbook 13s G2 Are Version-
LenovoThinkbook 13s G2 Itl Firmware Version < f9cn57ww
   LenovoThinkbook 13s G2 Itl Version-
LenovoThinkbook 13s G3 Acn Firmware Version < gmcn35ww
   LenovoThinkbook 13s G3 Acn Version-
LenovoThinkbook 13s G4 Iap Firmware Version < hwcn49ww
   LenovoThinkbook 13s G4 Iap Version-
LenovoThinkbook 13x G2 Iap Firmware Version < hxcn54ww
   LenovoThinkbook 13x G2 Iap Version-
LenovoThinkbook 14s G2 Itl Firmware Version < f9cn57ww
   LenovoThinkbook 14s G2 Itl Version-
LenovoYoga 9-15imh5 Firmware Version < epcn32ww
   LenovoYoga 9-15imh5 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.