CVE-2022-48188
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.
Affected (31)
Products: Lenovo: Ideacentre Aio 3 21itl7 Firmware, Ideacentre Aio 3 22itl6 Firmware, Ideacentre Aio 3 24itl6 Firmware, Ideacentre Aio 3 27itl6 Firmware, Thinkcentre M720e Firmware, Thinkcentre M720q Firmware, Thinkcentre M720s Firmware, Thinkcentre M720t Firmware, Thinkcentre M725s Firmware, Thinkcentre M75s Gen 2 Firmware, Thinkcentre M75t Gen 2 Firmware, Thinkcentre M920q Firmware, Thinkcentre M920s Firmware, Thinkcentre M920t Firmware, Thinkcentre M920x Firmware, Thinkcentre M920z Firmware, Ideacentre 510s 07icb Firmware, Ideacentre 510s 07ick Firmware, Ideacentre 720 18apr Firmware, V30a 22itl Firmware, V30a 24itl Firmware, V530s 07icb Firmware, V530s 07icr Firmware, Thinkstation P330 Tiny Firmware, Thinkstation P360 Ultra Firmware, Thinkstation P520 Firmware, Thinkstation P520c Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before o5akt33 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre Aio 3 21itl7 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before o5akt33 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre Aio 3 22itl6 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before o5akt33 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre Aio 3 24itl6 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before o5akt33 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre Aio 3 27itl6 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1zkt40a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M720e | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1ukt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M720q | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1ukt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M720s | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1ukt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M720t | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before m25kt63a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M725s | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before m46kt30a |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3bkt30a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M75s Gen 2 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before m46kt30a |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3akt4ca |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M75t Gen 2 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1ukt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M920q | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1ukt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M920s | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1ukt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M920t | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1ukt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M920x | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1mkt55a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M920z | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before m22kt48a |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before m22kt49a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre 510s 07icb | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before m30kt28a |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1zkt40a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre 510s 07ick | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before m25kt63a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre 720 18apr | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before o5akt33 |
| Running on/with | Platform Versions |
|---|---|
Lenovo V30a 22itl | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before o5akt33 |
| Running on/with | Platform Versions |
|---|---|
Lenovo V30a 24itl | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before m22kt49a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V530s 07icb | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1zkt40a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V530s 07icr | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1ukt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P330 Tiny | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before s0fkt27a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P360 Ultra | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before s03kt58a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P520 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before s03kt58a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P520c | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.