A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Project Subscriptions

Vendors Products
D330-10igl Subscribe
D330-10igl Firmware Subscribe
Ideapad 5 Pro-16ach6 Subscribe
Ideapad 5 Pro-16ach6 Firmware Subscribe
Ideapad 5 Pro-16ihu6 Subscribe
Ideapad 5 Pro-16ihu6 Firmware Subscribe
Ideapad 5 Pro 16arh7 Subscribe
Ideapad 5 Pro 16arh7 Firmware Subscribe
Ideapad Creator 5-16ach6 Subscribe
Ideapad Creator 5-16ach6 Firmware Subscribe
Ideapad Duet 3 10igl5 Subscribe
Ideapad Duet 3 10igl5 Firmware Subscribe
Ideapad Slim 7 Pro 16ach6 Subscribe
Ideapad Slim 7 Pro 16ach6 Firmware Subscribe
Notebook Subscribe
S540-15iml Subscribe
S540-15iml Firmware Subscribe
Slim 7 16arh7 Subscribe
Slim 7 16arh7 Firmware Subscribe
Thinkbook 13x Itg Subscribe
Thinkbook 13x Itg Firmware Subscribe
Thinkbook 14 G4\+ Ara Subscribe
Thinkbook 14 G4\+ Ara Firmware Subscribe
Thinkbook 14 G4\+ Iap Subscribe
Thinkbook 14 G4\+ Iap Firmware Subscribe
Thinkbook 16 G4\+ Ara Subscribe
Thinkbook 16 G4\+ Ara Firmware Subscribe
Thinkbook 16 G4\+ Iap Subscribe
Thinkbook 16 G4\+ Iap Firmware Subscribe
Thinkbook 16p Nx Arh Subscribe
Thinkbook 16p Nx Arh Firmware Subscribe
Thinkbook Plus G2 Itg Subscribe
Thinkbook Plus G2 Itg Firmware Subscribe
Thinkbook Plus G3 Iap Subscribe
Thinkbook Plus G3 Iap Firmware Subscribe
Yoga Duet 7-13iml05 Subscribe
Yoga Duet 7-13iml05 Firmware Subscribe
Yoga Duet 7-13itl6 Subscribe
Yoga Duet 7-13itl6-lte Subscribe
Yoga Duet 7-13itl6-lte Firmware Subscribe
Yoga Duet 7-13itl6 Firmware Subscribe
Yoga Slim 7-13acn05 Subscribe
Yoga Slim 7-13acn05 Firmware Subscribe
Yoga Slim 7-13itl05 Subscribe
Yoga Slim 7-13itl05 Firmware Subscribe
Yoga Slim 7 Carbon 13itl5 Subscribe
Yoga Slim 7 Carbon 13itl5 Firmware Subscribe
Yoga Slim 7 Pro 16ach6 Subscribe
Yoga Slim 7 Pro 16ach6 Firmware Subscribe
Yoga Slim 7 Pro 16arh7 Subscribe
Yoga Slim 7 Pro 16arh7 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-42807 A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the product Impact section of LEN-94952


Workaround

No workaround given by the vendor.

History

Thu, 19 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Lenovo notebook
CPEs cpe:2.3:h:lenovo:notebook:-:*:*:*:*:*:*:*
Vendors & Products Lenovo notebook
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-19T14:36:08.273Z

Reserved: 2022-10-07T19:59:25.920Z

Link: CVE-2022-3431

cve-icon Vulnrichment

Updated: 2024-08-03T01:07:06.619Z

cve-icon NVD

Status : Modified

Published: 2023-10-09T19:15:09.987

Modified: 2024-11-21T07:19:30.057

Link: CVE-2022-3431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses