Description
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Published: 2023-01-23
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the product Impact section of LEN-94952

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-42806 A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
History

Wed, 02 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Lenovo D330-10igl D330-10igl Firmware Ideapad 5 Pro 16arh7 Ideapad 5 Pro 16arh7 Firmware Ideapad 5 Pro 16iah7 Ideapad 5 Pro 16iah7 Firmware Ideapad Duet 3 10igl5 Ideapad Duet 3 10igl5 Firmware Ideapad Slim 7-14iil05 Ideapad Slim 7-14iil05 Firmware Ideapad Slim 7-14itl05 Ideapad Slim 7-14itl05 Firmware Ideapad Slim 7-15iil05 Ideapad Slim 7-15iil05 Firmware Slim 7-14are05 Slim 7-14are05 Firmware Slim 7-15imh05 Slim 7-15imh05 Firmware Slim 7-15itl05 Slim 7-15itl05 Firmware Slim 7 16arh7 Slim 7 16arh7 Firmware Thinkbook 13x Itg Thinkbook 13x Itg Firmware Thinkbook 14 G2 Are Thinkbook 14 G2 Are Firmware Thinkbook 14 G2 Itl Thinkbook 14 G2 Itl Firmware Thinkbook 14 G3 Acl Thinkbook 14 G3 Acl Firmware Thinkbook 14 G3 Itl Thinkbook 14 G3 Itl Firmware Thinkbook 14 G4\+ Ara Thinkbook 14 G4\+ Ara Firmware Thinkbook 14 G4\+ Iap Thinkbook 14 G4\+ Iap Firmware Thinkbook 14p G3 Arh Thinkbook 14p G3 Arh Firmware Thinkbook 14s Yoga Itl Thinkbook 14s Yoga Itl Firmware Thinkbook 15 G2 Are Thinkbook 15 G2 Are Firmware Thinkbook 15 G2 Itl Thinkbook 15 G2 Itl Firmware Thinkbook 15 G3 Acl Thinkbook 15 G3 Acl Firmware Thinkbook 15 G3 Itl Thinkbook 15 G3 Itl Firmware Thinkbook 15 G4 Aba Thinkbook 15 Gd Aba Firmware Thinkbook 15p G2 Ith Thinkbook 15p G2 Ith Firmware Thinkbook 15p Imp Thinkbook 15p Imp Firmware Thinkbook 16 G4\+ Ara Thinkbook 16 G4\+ Ara Firmware Thinkbook 16 G4\+ Iap Thinkbook 16 G4\+ Iap Firmware Thinkbook 16p G3 Arh Thinkbook 16p G3 Arh Firmware Thinkbook 16p Nx Arh Thinkbook 16p Nx Arh Firmware Thinkbook Plus G2 Itg Thinkbook Plus G2 Itg Firmware Thinkbook Plus G3 Iap Thinkbook Plus G3 Iap Firmware Yoga Creator 7-15imh05 Yoga Creator 7-15imh05 Firmware Yoga Duet 7-13iml05 Yoga Duet 7-13iml05 Firmware Yoga Duet 7-13itl6 Yoga Duet 7-13itl6-lte Yoga Duet 7-13itl6-lte Firmware Yoga Duet 7-13itl6 Firmware Yoga Slim 7-14are05 Yoga Slim 7-14are05 Firmware Yoga Slim 7-14iil05 Yoga Slim 7-14iil05 Firmware Yoga Slim 7-14itl05 Yoga Slim 7-14itl05 Firmware Yoga Slim 7-15iil05 Yoga Slim 7-15iil05 Firmware Yoga Slim 7-15imh05 Yoga Slim 7-15imh05 Firmware Yoga Slim 7-15itl05 Yoga Slim 7-15itl05 Firmware Yoga Slim 7 Pro 16arh7 Yoga Slim 7 Pro 16arh7 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-04-02T15:01:31.058Z

Reserved: 2022-10-07T19:58:27.731Z

Link: CVE-2022-3430

cve-icon Vulnrichment

Updated: 2024-08-03T01:07:06.525Z

cve-icon NVD

Status : Modified

Published: 2023-01-23T17:15:10.647

Modified: 2024-11-21T07:19:29.873

Link: CVE-2022-3430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses