6.7

CVE-2023-5078

A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.

Data is provided by the National Vulnerability Database (NVD)
LenovoThinkpad S2 Gen 8 Firmware Version-
   LenovoThinkpad S2 Gen 8 Version-
LenovoThinkpad L14 Gen 3 Firmware Version < 1.23
   LenovoThinkpad L14 Gen 3 Version-
LenovoThinkpad L14 Gen 4 Firmware Version < 1.1
   LenovoThinkpad L14 Gen 4 Version-
LenovoThinkpad L15 Gen 3 Firmware Version < 1.23
   LenovoThinkpad L15 Gen 3 Version-
LenovoThinkpad L15 Gen 4 Firmware Version < 1.1
   LenovoThinkpad L15 Gen 4 Version-
LenovoThinkpad L13 Gen 3 Firmware Version < 1.19
   LenovoThinkpad L13 Gen 3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.112
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H