6.7

CVE-2023-43578

A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. 

Data is provided by the National Vulnerability Database (NVD)
LenovoIdeacentre C5-14imb05 Firmware Version < o4hkt3ca
   LenovoIdeacentre C5-14imb05 Version-
LenovoIdeacentre 3-07ada05 Firmware Version < o4fkt39a
   LenovoIdeacentre 3-07ada05 Version-
LenovoIdeacentre 3-07imb05 Firmware Version < m2vkt21a
   LenovoIdeacentre 3-07imb05 Version-
LenovoIdeacentre 5 14iab7 Firmware Version < m42kt46a
   LenovoIdeacentre 5 14iab7 Version-
LenovoIdeacentre 5 14irb8 Firmware Version < m4ukt36a
   LenovoIdeacentre 5 14irb8 Version-
LenovoThinkcentre M90t Gen 3 Firmware Version < m40kt45a
   LenovoThinkcentre M90t Gen 3 Version-
LenovoThinkcentre M90t Firmware Version < m2tkt55a
   LenovoThinkcentre M90t Version-
LenovoThinkcentre M90s Gen 3 Firmware Version < m40kt45a
   LenovoThinkcentre M90s Gen 3 Version-
LenovoThinkcentre M90s Firmware Version < m2tkt55a
   LenovoThinkcentre M90s Version-
LenovoThinkcentre M90a Gen 3 Firmware Version < m4ikt1da
   LenovoThinkcentre M90a Gen 3 Version-
LenovoThinkcentre M90a Gen 2 Firmware Version < m3lkt2aa
   LenovoThinkcentre M90a Gen 2 Version-
LenovoThinkcentre M90a Firmware Version < m2rkt57a
   LenovoThinkcentre M90a Version-
LenovoThinkcentre M80t Gen 3 Firmware Version < m40kt45a
   LenovoThinkcentre M80t Gen 3 Version-
LenovoThinkcentre M80t Firmware Version < m2tkt55a
   LenovoThinkcentre M80t Version-
LenovoThinkcentre M80s Gen 3 Firmware Version < m40kt45a
   LenovoThinkcentre M80s Gen 3 Version-
LenovoThinkcentre M80s Firmware Version < m2tkt55a
   LenovoThinkcentre M80s Version-
LenovoThinkcentre M80q Firmware Version-
   LenovoThinkcentre M80q Version-
LenovoThinkcentre M75n Firmware Version < m33kt29a
   LenovoThinkcentre M75n Version-
LenovoThinkcentre M70t Gen 3 Firmware Version < m41kt45a
   LenovoThinkcentre M70t Gen 3 Version-
LenovoThinkcentre M70t Firmware Version < m2tkt55a
   LenovoThinkcentre M70t Version-
LenovoThinkcentre M70s Gen 3 Firmware Version < m41kt45a
   LenovoThinkcentre M70s Gen 3 Version-
LenovoThinkcentre M70s Firmware Version < m2tkt55a
   LenovoThinkcentre M70s Version-
LenovoThinkcentre M70q Firmware Version-
   LenovoThinkcentre M70q Version-
LenovoThinkcentre M70c Firmware Version < m2vkt21a
   LenovoThinkcentre M70c Version-
LenovoThinkcentre M630e Firmware Version < m28kt42a
   LenovoThinkcentre M630e Version-
LenovoThinkcentre M625q Firmware Version-
   LenovoThinkcentre M625q Version-
LenovoLoq 17irb8 Firmware Version < m4ukt36a
   LenovoLoq 17irb8 Version-
LenovoLegion T5 26iab7 Firmware Version < o5lkt2ba
   LenovoLegion T5 26iab7 Version-
LenovoLegion T7-34imz5 Firmware Version < o5fkt17a
   LenovoLegion T7-34imz5 Version-
LenovoLegion T7-34iaz7 Firmware Version < o5hkt2ca
   LenovoLegion T7-34iaz7 Version-
LenovoLegion T7 34irz8 Firmware Version < o5ukt1fa
   LenovoLegion T7 34irz8 Version-
LenovoLegion T5 26irb8 Firmware Version < o5tkt1ca
   LenovoLegion T5 26irb8 Version-
LenovoIdeacentre Mini 5 01iaq7 Firmware Version < o53kt10a
   LenovoIdeacentre Mini 5 01iaq7 Version-
LenovoIdeacentre G5-14imb05 Firmware Version < o4hkt3ca
   LenovoIdeacentre G5-14imb05 Version-
LenovoIdeacentre G5-14amr05 Firmware Version < o4zkt2ba
   LenovoIdeacentre G5-14amr05 Version-
LenovoIdeacentre Aio 5 27iah7 Firmware Version < o5rkt41a
   LenovoIdeacentre Aio 5 27iah7 Version-
LenovoIdeacentre Aio 5 24iah7 Firmware Version < o5rkt41a
   LenovoIdeacentre Aio 5 24iah7 Version-
LenovoIdeacentre Aio 3-27itl6 Firmware Version < o5akt34a
   LenovoIdeacentre Aio 3-27itl6 Version-
LenovoIdeacentre Aio 3-27imb05 Firmware Version < o4rkt31a
   LenovoIdeacentre Aio 3-27imb05 Version-
LenovoIdeacentre Aio 3-24itl6 Firmware Version < o5akt34a
   LenovoIdeacentre Aio 3-24itl6 Version-
LenovoIdeacentre Aio 3-24imb05 Firmware Version < o4rkt31a
   LenovoIdeacentre Aio 3-24imb05 Version-
LenovoIdeacentre Aio 3-24iil5 Firmware Version < o56kt24a
   LenovoIdeacentre Aio 3-24iil5 Version-
LenovoIdeacentre Aio 3-24alc6 Firmware Version < o5bkt25a
   LenovoIdeacentre Aio 3-24alc6 Version-
LenovoIdeacentre Aio 3-22itl6 Firmware Version < o5akt34a
   LenovoIdeacentre Aio 3-22itl6 Version-
LenovoIdeacentre Aio 3-22imb05 Firmware Version < o4rkt31a
   LenovoIdeacentre Aio 3-22imb05 Version-
LenovoIdeacentre Aio 3-22iil5 Firmware Version < o56kt24a
   LenovoIdeacentre Aio 3-22iil5 Version-
LenovoIdeacentre Aio 3 27iap7 Firmware Version < o5nkt33a
   LenovoIdeacentre Aio 3 27iap7 Version-
LenovoIdeacentre Aio 3 24iap7 Firmware Version < o5nkt33a
   LenovoIdeacentre Aio 3 24iap7 Version-
LenovoIdeacentre Aio 3 22iap7 Firmware Version < o5nkt33a
   LenovoIdeacentre Aio 3 22iap7 Version-
LenovoIdeacentre Aio 3 21itl7 Firmware Version < o5akt34a
   LenovoIdeacentre Aio 3 21itl7 Version-
LenovoIdeacentre 5-14iob6 Firmware Version < m3gkt3da
   LenovoIdeacentre 5-14iob6 Version-
LenovoIdeacentre 5-14imb05 Firmware Version < o4hkt3ca
   LenovoIdeacentre 5-14imb05 Version-
LenovoV30a-22iml Firmware Version < m37kt31a
   LenovoV30a-22iml Version-
LenovoV30a-22itl Firmware Version < o5akt34a
   LenovoV30a-22itl Version-
LenovoV30a-24iml Firmware Version < m37kt31a
   LenovoV30a-24iml Version-
LenovoV30a-24itl Firmware Version < o5akt34a
   LenovoV30a-24itl Version-
LenovoV50a-22imb Firmware Version < m36kt32a
   LenovoV50a-22imb Version-
LenovoV50a-24imb Firmware Version < m36kt32a
   LenovoV50a-24imb Version-
LenovoV50s-07imb Firmware Version < m2vkt21a
   LenovoV50s-07imb Version-
LenovoV50t-13imb Firmware Version < o4hkt3ca
   LenovoV50t-13imb Version-
LenovoV50t-13imh Firmware Version < m4pkt16a
   LenovoV50t-13imh Version-
LenovoV50t-13iob Firmware Version < m3gkt3da
   LenovoV50t-13iob Version-
LenovoV55t Gen 2 13acn Firmware Version < o5jkt2ca
   LenovoV55t Gen 2 13acn Version-
LenovoYoga Aio 7 27arh7 Firmware Version-
   LenovoYoga Aio 7 27arh7 Version-
LenovoYoga Aio 7-27arh6 Firmware Version-
   LenovoYoga Aio 7-27arh6 Version-
LenovoThinkedge Se30 Firmware Version-
   LenovoThinkedge Se30 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.102
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.