8.4
CVE-2023-4030
- EPSS 0.07%
- Veröffentlicht 17.08.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:34:15
- Quelle psirt@lenovo.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Thinkpad T15 Gen 2 Firmware Version-
Lenovo ≫ Thinkpad P14s Gen 2 Firmware Version-
Lenovo ≫ Thinkpad P15s Gen 2 Firmware Version-
Lenovo ≫ Thinkpad T14 Gen 2 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.226 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
psirt@lenovo.com | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-636 Not Failing Securely ('Failing Open')
When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.