CVE-2022-3746
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.
Affected (87)
Products: Lenovo: Ideapad 1 14iau7 Firmware, Ideapad 1 14igl7 Firmware, Ideapad 1 15iau7 Firmware, Ideapad 1 15igl7 Firmware, Ideapad 1 14ijl7 Firmware, Ideapad 1 15ijl7 Firmware, Ideapad 3 14iau7 Firmware, Ideapad 3 15iau7 Firmware, Ideapad 3 17iau7 Firmware, Ideapad 3 15igl05 Firmware, Ideapad 3 17iil05 Firmware, Ideapad 3 17itl6 Firmware, Ideapad 5 15ial7 Firmware, Ideapad 5 15itl05 Firmware, L3 15iml05 Firmware, L3 15itl6 Firmware, Legion 5 15iah7 Firmware, Legion 5 15iah7h Firmware, Legion 5 Pro 16iah7 Firmware, Legion 5 Pro 16iah7h Firmware, Legion 5 Pro 16ith6 Firmware, Legion 5 Pro 16ith6h Firmware, Legion 5 15imh05 Firmware, Legion 5 15imh05h Firmware, Legion 5 15imh6 Firmware, Legion 5 15ith6 Firmware, Legion 5 15ith6h Firmware, Legion 5 17imh05 Firmware, Legion 5 17imh05h Firmware, Legion 5 17ith6 Firmware, Legion 5 17ith6h Firmware, Legion 5p 15imh05 Firmware, Legion 5p 15imh05h Firmware, Legion 7 16iax7 Firmware, Legion 7 16ithg6 Firmware, S14 G2 Itl Firmware, S14 G3 Iap Firmware, Slim 7 14iap7 Firmware, Slim 7 Carbon 13iap7 Firmware, Slim 7 Prox 14iah7 Firmware, Slim 9 14iap7 Firmware, Thinkbook 15p Imh Firmware, V14 G2 Ijl Firmware, V14 G3 Iap Firmware, V15 G2 Ijl Firmware, V15 G3 Iap Firmware, V17 G3 Iap Firmware, S540 13itl Firmware, Slim 7 Pro 14ihu5 Firmware, Slim 9 14itl05 Firmware, Thinkbook 15p G2 Ith Firmware, V14 G1 Iml Firmware, V14 G2 Itl Firmware, V14 Igl Firmware, V15 G1 Iml Firmware, V15 G2 Itl Firmware, V15 Igl Firmware, V17 G2 Itl Firmware, V17 Iil Firmware, Yoga 7 14ial7 Firmware, Yoga 7 16iah7 Firmware, Yoga 7 16iap7 Firmware, Yoga 7 14itl5 Firmware, Yoga 7 15itl5 Firmware, Yoga 9 14iap7 Firmware, Yoga Slim 7 Carbon 13iap7 Firmware, Yoga Slim 7 Pro 14iah7 Firmware, Yoga Slim 7 Pro 14iap7 Firmware, Yoga Slim 7 Pro 14ihu5 Firmware, Yoga Slim 7 Pro 14ihu5 O Firmware, Yoga Slim 7 Pro 14itl5 Firmware, Yoga Slim 7 Prox 14iah7 Firmware, Yoga Slim 9 14iap7 Firmware, Yoga Slim 9 14itl05 Firmware, Ideapad 3 14igl05 Firmware, Ideapad 3 14iil05 Firmware, Ideapad 3 14iml05 Firmware, Ideapad 3 14itl05 Firmware, Ideapad 3 14itl6 Firmware, Ideapad 3 15iil05 Firmware, Ideapad 3 15iml05 Firmware, Ideapad 3 15itl05 Firmware, Ideapad 3 15itl6 Firmware, Ideapad 3 17iml05 Firmware, Ideapad 5 15iil05 Firmware, Ideapad Creator 5 15imh05 Firmware, Ideapad Gaming 3 15imh05 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before jkcn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 1 14iau7 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before kkcn15ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 1 14igl7 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before jkcn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 1 15iau7 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before kkcn15ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 1 15igl7 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before htcn31ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 1 14ijl7 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before htcn31ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 1 15ijl7 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before jkcn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14iau7 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before jkcn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15iau7 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before jkcn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 17iau7 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before dvcn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15igl05 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before emcn56ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 17iil05 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before ggcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 17itl6 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before jbcn27ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 5 15ial7 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before fhcn70ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 5 15itl05 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before ejcn30ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo L3 15iml05 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before gfcn29ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo L3 15itl6 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before j2cn49ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15iah7 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before j2cn49ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15iah7h | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before j2cn49ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16iah7 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before j2cn49ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16iah7h | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn52ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16ith6 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn52ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16ith6h | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before efcn58ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15imh05 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before efcn58ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15imh05h | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before g8cn22ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15imh6 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn52ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ith6 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn52ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ith6h | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before efcn58ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17imh05 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before efcn58ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17imh05h | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn52ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17ith6 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn52ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17ith6h | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before efcn58ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5p 15imh05 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before efcn58ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5p 15imh05h | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before k1cn40ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 7 16iax7 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn52ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 7 16ithg6 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before ggcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S14 G2 Itl | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before jkcn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S14 G3 Iap | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before jhcn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Slim 7 14iap7 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before k2cn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Slim 7 Carbon 13iap7 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before hmcn41ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Slim 7 Prox 14iah7 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before j3cn49ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Slim 9 14iap7 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before f6cn26ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkbook 15p Imh | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before htcn31ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V14 G2 Ijl | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before jkcn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V14 G3 Iap | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before htcn31ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V15 G2 Ijl | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before jkcn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V15 G3 Iap | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before jkcn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V17 G3 Iap | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before fzcn26ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S540 13itl | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before fjcn74ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Slim 7 Pro 14ihu5 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before escn56ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Slim 9 14itl05 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before hjcn32ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkbook 15p G2 Ith | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before dxcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V14 G1 Iml | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before ggcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V14 G2 Itl | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before dvcn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V14 Igl | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before dxcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V15 G1 Iml | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before ggcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V15 G2 Itl | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before dvcn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V15 Igl | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before ggcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V17 G2 Itl | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before emcn56ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V17 Iil | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before j1cn35ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga 7 14ial7 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before j1cn35ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga 7 16iah7 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before j1cn35ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga 7 16iap7 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before f5cn59ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga 7 14itl5 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before f5cn59ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga 7 15itl5 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before hncn42ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga 9 14iap7 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before k2cn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga Slim 7 Carbon 13iap7 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before krcn14ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga Slim 7 Pro 14iah7 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before jhcn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga Slim 7 Pro 14iap7 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before fjcn74ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga Slim 7 Pro 14ihu5 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before fjcn74ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga Slim 7 Pro 14ihu5 O | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before fjcn74ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga Slim 7 Pro 14itl5 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before hmcn41ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga Slim 7 Prox 14iah7 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before j3cn49ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga Slim 9 14iap7 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before escn56ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga Slim 9 14itl05 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before dvcn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14igl05 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before emcn56ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14iil05 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before dxcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14iml05 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before gccn32ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14itl05 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before ggcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14itl6 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before emcn56ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15iil05 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before dxcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15iml05 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before gccn32ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15itl05 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before ggcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15itl6 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before dxcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 17iml05 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before dpcn58ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 5 15iil05 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before egcn40ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Creator 5 15imh05 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before egcn40ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Gaming 3 15imh05 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.