CVE-2023-4028
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
Affected (29)
Products: Lenovo: 13w Yoga Firmware, 13w Yoga Gen 2 Firmware, Ideapad 1 11ada05 Firmware, Ideapad 1 11igl05 Firmware, Ideapad 1 14ada05 Firmware, Ideapad 1 14igl05 Firmware, Flex 5 14alc05 Firmware, Flex 5 14are05 Firmware, Flex 5 14iil05 Firmware, Flex 5 14itl05 Firmware, Flex 5 15alc05 Firmware, Flex 5 15iil05 Firmware, Flex 5 15itl05 Firmware, Ideapad Flex 5 14abr8 Firmware, Ideapad Flex 5 14alc7 Firmware, Ideapad Flex 5 14iau7 Firmware, Ideapad Flex 5 14iru8 Firmware, Ideapad Flex 5 16abr8 Firmware, Ideapad Flex 5 16alc7 Firmware, Ideapad Flex 5 16iau7 Firmware, Ideapad Flex 5 16iru8 Firmware, Flex 7 14iru8 Firmware, Thinkbook 13s G2 Are Firmware, Thinkbook 13s G2 Itl Firmware, Thinkbook 13s G3 Acn Firmware, Thinkbook 13s G4 Iap Firmware, Thinkbook 13x G2 Iap Firmware, Thinkbook 14s G2 Itl Firmware, Yoga 9 15imh5 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before jacn38ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo 13w Yoga | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before kbcn20ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo 13w Yoga Gen 2 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before fqcn29ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 1 11ada05 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before dwcn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 1 11igl05 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before fqcn29ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 1 14ada05 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before dwcn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 1 14igl05 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before gjcn32ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex 5 14alc05 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before eecn43ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex 5 14are05 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before eccn45ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex 5 14iil05 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before fxcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex 5 14itl05 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before gjcn32ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex 5 15alc05 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before eccn45ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex 5 15iil05 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before fxcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex 5 15itl05 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before l7cn17ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Flex 5 14abr8 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before jccn35ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Flex 5 14alc7 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before j7cn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Flex 5 14iau7 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before l6cn20ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Flex 5 14iru8 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before l7cn17ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Flex 5 16abr8 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before jccn35ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Flex 5 16alc7 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before j7cn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Flex 5 16iau7 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before l6cn20ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Flex 5 16iru8 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before l6cn20ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex 7 14iru8 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before fvcn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkbook 13s G2 Are | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before f9cn57ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkbook 13s G2 Itl | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before gmcn35ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkbook 13s G3 Acn | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before hwcn49ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkbook 13s G4 Iap | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before hxcn54ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkbook 13x G2 Iap | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before f9cn57ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkbook 14s G2 Itl | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before epcn32ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga 9 15imh5 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.