6.8
CVE-2024-7756
- EPSS 0.02%
- Veröffentlicht 13.09.2024 18:15:06
- Zuletzt bearbeitet 14.09.2024 11:47:14
- Quelle psirt@lenovo.com
- CVE-Watchlists
- Unerledigt
A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerlenovo
≫
Produkt
thinkpad_l390_yoga_firmware
Default Statusunaffected
Version <
1.47
Version
0
Status
affected
Herstellerlenovo
≫
Produkt
10w_firmware
Default Statusunaffected
Version <
jscn28ww
Version
0
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.022 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@lenovo.com | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-489 Active Debug Code
The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.