6.7

CVE-2023-45079

A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables. 

Data is provided by the National Vulnerability Database (NVD)
LenovoIdeacentre C5-14imb05 Firmware Version < o4hkt3ca
   LenovoIdeacentre C5-14imb05 Version-
LenovoIdeacentre 3-07ada05 Firmware Version < o4fkt39a
   LenovoIdeacentre 3-07ada05 Version-
LenovoIdeacentre 3-07imb05 Firmware Version < m2vkt21a
   LenovoIdeacentre 3-07imb05 Version-
LenovoIdeacentre G5-14imb05 Firmware Version < o4hkt3ca
   LenovoIdeacentre G5-14imb05 Version-
LenovoIdeacentre 5-14iob6 Firmware Version < m3gkt3da
   LenovoIdeacentre 5-14iob6 Version-
LenovoIdeacentre G5-14amr05 Firmware Version < o4zkt2ba
   LenovoIdeacentre G5-14amr05 Version-
LenovoIdeacentre G5-14imb05 Firmware Version < o4hkt3ca
   LenovoIdeacentre G5-14imb05 Version-
LenovoIdeacentre Mini 5 01iaq7 Firmware Version < o53kt10a
   LenovoIdeacentre Mini 5 01iaq7 Version-
LenovoLegion T7-34imz5 Firmware Version < o5fkt17a
   LenovoLegion T7-34imz5 Version-
LenovoThinkcentre M625q Firmware Version < m1wkt52a
   LenovoThinkcentre M625q Version-
LenovoThinkcentre M630e Firmware Version-
   LenovoThinkcentre M630e Version-
LenovoThinkcentre M70a Firmware Version < m2skt29a
   LenovoThinkcentre M70a Version-
LenovoThinkcentre M920x Firmware Version < m1ukt72a
   LenovoThinkcentre M920x Version-
LenovoThinkcentre M920t Firmware Version < m1ukt72a
   LenovoThinkcentre M920t Version-
LenovoThinkcentre M920s Firmware Version < m1ukt72a
   LenovoThinkcentre M920s Version-
LenovoThinkcentre M920q Firmware Version < m1ukt72a
   LenovoThinkcentre M920q Version-
LenovoThinkcentre M90t Firmware Version < m2tkt55a
   LenovoThinkcentre M90t Version-
LenovoThinkcentre M90s Firmware Version < m2tkt55a
   LenovoThinkcentre M90s Version-
LenovoThinkcentre M90q Tiny Firmware Version < m2wkt5aa
   LenovoThinkcentre M90q Tiny Version-
LenovoThinkcentre M90a Firmware Version < m2rkt57a
   LenovoThinkcentre M90a Version-
LenovoThinkcentre M80t Firmware Version < m2tkt55a
   LenovoThinkcentre M80t Version-
LenovoThinkcentre M80s Firmware Version < m2tkt55a
   LenovoThinkcentre M80s Version-
LenovoThinkcentre M80q Firmware Version < m2wkt5aa
   LenovoThinkcentre M80q Version-
LenovoThinkcentre M75q Gen 2 Firmware Version < m47kt30a
   LenovoThinkcentre M75q Gen 2 Version-
LenovoThinkcentre M75n Firmware Version < m33kt27a
   LenovoThinkcentre M75n Version-
LenovoThinkcentre M720t Firmware Version < m1ukt72a
   LenovoThinkcentre M720t Version-
LenovoThinkcentre M720s Firmware Version < m1ukt72a
   LenovoThinkcentre M720s Version-
LenovoThinkcentre M720q Firmware Version < m1ukt72a
   LenovoThinkcentre M720q Version-
LenovoThinkcentre M70t Firmware Version < m2tkt55a
   LenovoThinkcentre M70t Version-
LenovoThinkcentre M70s Firmware Version < m2tkt55a
   LenovoThinkcentre M70s Version-
LenovoThinkcentre M70q Firmware Version < m2wkt5aa
   LenovoThinkcentre M70q Version-
LenovoThinkcentre M70c Firmware Version < m2vkt21a
   LenovoThinkcentre M70c Version-
LenovoV50t-13iob G2 Firmware Version < m3gkt3da
   LenovoV50t-13iob G2 Version-
LenovoV55t Gen 2 13acn Firmware Version < o5jkt23a
   LenovoV55t Gen 2 13acn Version-
LenovoV50t-13imh Firmware Version < m4pkt13a
   LenovoV50t-13imh Version-
LenovoV50t-13imb Firmware Version < o4hkt3ca
   LenovoV50t-13imb Version-
LenovoV50s-07imb Firmware Version < m2vkt21a
   LenovoV50s-07imb Version-
LenovoV50a-24imb Firmware Version < m36kt32a
   LenovoV50a-24imb Version-
LenovoV50a-22imb Firmware Version < m36kt32a
   LenovoV50a-22imb Version-
LenovoV30a-24iml Firmware Version < m37kt31a
   LenovoV30a-24iml Version-
LenovoV30a-22iml Firmware Version < m37kt31a
   LenovoV30a-22iml Version-
LenovoThinkcentre M70c Firmware Version < m2vkt21a
   LenovoThinkcentre M70c Version-
LenovoThinkedge Se30 Firmware Version < m3fkt2da
   LenovoThinkedge Se30 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.089
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.