Description

A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.

Published: 2023-10-30
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-106014.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Lenovo Thinkpad 25 Thinkpad 25 Firmware Thinkpad L560 Thinkpad L560 Firmware Thinkpad P50 Thinkpad P50 Firmware Thinkpad P50s Thinkpad P50s Firmware Thinkpad P70 Thinkpad P70 Firmware Thinkpad T470 Thinkpad T470 Firmware Thinkpad T470s Thinkpad T470s Firmware Thinkpad T560 Thinkpad T560 Firmware Thinkpad X1 Carbon 4th Gen Thinkpad X1 Carbon 4th Gen Firmware Thinkpad X1 Yoga 1st Gen Thinkpad X1 Yoga 1st Gen Firmware Thinkpad X260 Thinkpad X260 Firmware Thinkpad X270 Thinkpad X270 Firmware Thinkpad Yoga 260 Thinkpad Yoga 260 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T01:41:45.637Z

Reserved: 2022-12-16T21:26:17.285Z

Link: CVE-2022-4575

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-10-30T15:15:40.493

Modified: 2024-11-21T07:35:31.517

Link: CVE-2022-4575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses