← Back

CVE-2022-3431

nvd nist
Published: Oct 9, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Affected (25)

25 products
Ideapad Creator 5 16ach6 Firmware
Ideapad 5 Pro 16ihu6 Firmware
Ideapad 5 Pro 16ach6 Firmware
Yoga Slim 7 13itl05 Firmware
Yoga Slim 7 13acn05 Firmware
Yoga Slim 7 Pro 16arh7 Firmware
Yoga Slim 7 Pro 16ach6 Firmware
Yoga Duet 7 13itl6 Lte Firmware
Yoga Duet 7 13itl6 Firmware
Yoga Duet 7 13iml05 Firmware
Thinkbook Plus G3 Iap Firmware
Thinkbook Plus G2 Itg Firmware
Thinkbook 16p Nx Arh Firmware
Thinkbook 16 G4+ Iap Firmware
Thinkbook 16 G4+ Ara Firmware
Thinkbook 14 G4+ Iap Firmware
Thinkbook 14 G4+ Ara Firmware
Thinkbook 13x Itg Firmware
S540 15iml Firmware
Slim 7 16arh7 Firmware
Ideapad Duet 3 10igl5 Firmware
Ideapad 5 Pro 16arh7 Firmware
D330 10igl Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before gscn34ww
Running on/withPlatform Versions
Lenovo
Ideapad Creator 5 16ach6
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before grcn22ww
Running on/withPlatform Versions
Lenovo
Ideapad 5 Pro 16ihu6
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before gscn34ww
Running on/withPlatform Versions
Lenovo
Ideapad 5 Pro 16ach6
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before f7cn39ww
Running on/withPlatform Versions
Lenovo
Yoga Slim 7 13itl05
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before ghcn28ww
Running on/withPlatform Versions
Lenovo
Yoga Slim 7 13acn05
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before klcn15ww
Running on/withPlatform Versions
Lenovo
Yoga Slim 7 Pro 16arh7
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before hucn16ww
Running on/withPlatform Versions
Lenovo
Yoga Slim 7 Pro 16ach6
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before f7cn39ww
Running on/withPlatform Versions
Lenovo
Yoga Slim 7 Carbon 13itl5
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before gpcn24ww
Running on/withPlatform Versions
Lenovo
Yoga Duet 7 13itl6 Lte
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before gpcn24ww
Running on/withPlatform Versions
Lenovo
Yoga Duet 7 13itl6
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before ercn30ww
Running on/withPlatform Versions
Lenovo
Yoga Duet 7 13iml05
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before k6cn29ww
Running on/withPlatform Versions
Lenovo
Thinkbook Plus G3 Iap
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before gycn31ww
Running on/withPlatform Versions
Lenovo
Thinkbook Plus G2 Itg
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before kjcn27ww
Running on/withPlatform Versions
Lenovo
Thinkbook 16p Nx Arh
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before hycn40ww
Running on/withPlatform Versions
Lenovo
Thinkbook 16 G4+ Iap
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before j6cn40ww
Running on/withPlatform Versions
Lenovo
Thinkbook 16 G4+ Ara
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before hycn40ww
Running on/withPlatform Versions
Lenovo
Thinkbook 14 G4+ Iap
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before j6cn40ww
Running on/withPlatform Versions
Lenovo
Thinkbook 14 G4+ Ara
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before hlcn30ww
Running on/withPlatform Versions
Lenovo
Thinkbook 13x Itg
All versions
Configuration T
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before hucn16ww
Running on/withPlatform Versions
Lenovo
Ideapad Slim 7 Pro 16ach6
All versions
Configuration U
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before cncn22ww
Running on/withPlatform Versions
Lenovo
S540 15iml
All versions
Configuration V
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before klcn15ww
Running on/withPlatform Versions
Lenovo
Slim 7 16arh7
All versions
Configuration W
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before eqcn37ww
Running on/withPlatform Versions
Lenovo
Ideapad Duet 3 10igl5
All versions
Configuration X
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before j4cn33ww
Running on/withPlatform Versions
Lenovo
Ideapad 5 Pro 16arh7
All versions
Configuration Y
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before g0cn11ww
Running on/withPlatform Versions
Lenovo
D330 10igl
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.