Metrics
No CVSS v4.0
Attack Vector Local
Attack Complexity Low
Privileges Required High
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
No CVSS v2
This CVE is not in the KEV list.
The EPSS score is 0.00032.
Exploitation none
Automatable no
Technical Impact total
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Ideacentre 510s-07icb
Subscribe
Ideacentre 510s-07icb Firmware
Subscribe
Ideacentre 510s-07ick
Subscribe
Ideacentre 510s-07ick Firmware
Subscribe
Ideacentre 720-18apr
Subscribe
Ideacentre 720-18apr Firmware
Subscribe
Ideacentre Aio 3-22itl6
Subscribe
Ideacentre Aio 3-22itl6 Firmware
Subscribe
Ideacentre Aio 3-24itl6
Subscribe
Ideacentre Aio 3-24itl6 Firmware
Subscribe
Ideacentre Aio 3-27itl6
Subscribe
Ideacentre Aio 3-27itl6 Firmware
Subscribe
Ideacentre Aio 3 21itl7
Subscribe
Ideacentre Aio 3 21itl7 Firmware
Subscribe
Thinkcentre M720e
Subscribe
Thinkcentre M720e Firmware
Subscribe
Thinkcentre M720q
Subscribe
Thinkcentre M720q Firmware
Subscribe
Thinkcentre M720s
Subscribe
Thinkcentre M720s Firmware
Subscribe
Thinkcentre M720t
Subscribe
Thinkcentre M720t Firmware
Subscribe
Thinkcentre M725s
Subscribe
Thinkcentre M725s Firmware
Subscribe
Thinkcentre M75s Gen 2
Subscribe
Thinkcentre M75s Gen 2 Firmware
Subscribe
Thinkcentre M75t Gen 2
Subscribe
Thinkcentre M75t Gen 2 Firmware
Subscribe
Thinkcentre M920q
Subscribe
Thinkcentre M920q Firmware
Subscribe
Thinkcentre M920s
Subscribe
Thinkcentre M920s Firmware
Subscribe
Thinkcentre M920t
Subscribe
Thinkcentre M920t Firmware
Subscribe
Thinkcentre M920x
Subscribe
Thinkcentre M920x Firmware
Subscribe
Thinkcentre M920z
Subscribe
Thinkcentre M920z Firmware
Subscribe
Thinkstation P330 Tiny
Subscribe
Thinkstation P330 Tiny Firmware
Subscribe
Thinkstation P360 Ultra
Subscribe
Thinkstation P360 Ultra Firmware
Subscribe
Thinkstation P520
Subscribe
Thinkstation P520 Firmware
Subscribe
Thinkstation P520c
Subscribe
Thinkstation P520c Firmware
Subscribe
V30a-22itl
Subscribe
V30a-22itl Firmware
Subscribe
V30a-24itl
Subscribe
V30a-24itl Firmware
Subscribe
V530s-07icb
Subscribe
V530s-07icb Firmware
Subscribe
V530s-07icr
Subscribe
V530s-07icr Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
Configuration 24 [-]
| AND |
|
Configuration 25 [-]
| AND |
|
Configuration 26 [-]
| AND |
|
Configuration 27 [-]
| AND |
|
Configuration 28 [-]
| AND |
|
Configuration 29 [-]
| AND |
|
Configuration 30 [-]
| AND |
|
Configuration 31 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-50899 | A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code. |
Solution
Update system firmware to the version (or newer) indicated for your model in the related Lenovo advisory: https://support.lenovo.com/us/en/product_security/LEN-124495 https://support.lenovo.com/us/en/product_security/LEN-124495
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-124495 |
|
Wed, 08 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2025-01-08T15:50:42.163Z
Reserved: 2022-12-29T17:29:25.496Z
Link: CVE-2022-48188
Updated: 2024-08-03T15:10:58.423Z
Status : Modified
Published: 2023-06-05T22:15:11.563
Modified: 2024-11-21T07:32:56.600
Link: CVE-2022-48188
No data.
OpenCVE Enrichment
No data.
EUVD