Description
A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
Published: 2023-11-08
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-141775

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-49396 A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
History

No history.

Subscriptions

Lenovo Ideacentre 3-07ada05 Ideacentre 3-07ada05 Firmware Ideacentre 3-07imb05 Ideacentre 3-07imb05 Firmware Ideacentre 5-14iob6 Ideacentre 5-14iob6 Firmware Ideacentre C5-14imb05 Ideacentre C5-14imb05 Firmware Ideacentre Creator 5-14iob6 Ideacentre Creator 5-14iob6 Firmware Ideacentre G5-14amr05 Ideacentre G5-14amr05 Firmware Ideacentre G5-14imb05 Ideacentre G5-14imb05 Firmware Ideacentre Gaming 5-14iob6 Ideacentre Gaming 5-14iob6 Firmware Ideacentre Mini 5-01imh05 Ideacentre Mini 5-01imh05 Firmware Ideacentre Mini 5 01iaq7 Ideacentre Mini 5 01iaq7 Firmware Legion T7-34imz5 Legion T7-34imz5 Firmware Thinkcentre M625q Thinkcentre M625q Firmware Thinkcentre M630e Thinkcentre M630e Firmware Thinkcentre M70a Thinkcentre M70a Firmware Thinkcentre M70c Thinkcentre M70c Firmware Thinkcentre M70q Thinkcentre M70q Firmware Thinkcentre M70s Thinkcentre M70s Firmware Thinkcentre M70t Thinkcentre M70t Firmware Thinkcentre M720q Thinkcentre M720q Firmware Thinkcentre M720s Thinkcentre M720s Firmware Thinkcentre M720t Thinkcentre M720t Firmware Thinkcentre M75n Thinkcentre M75n Firmware Thinkcentre M75q Gen 2 Thinkcentre M75q Gen 2 Firmware Thinkcentre M75s Gen 2 Thinkcentre M75s Gen 2 Firmware Thinkcentre M75t Gen 2 Thinkcentre M75t Gen 2 Firmware Thinkcentre M80q Thinkcentre M80q Firmware Thinkcentre M80s Thinkcentre M80s Firmware Thinkcentre M80t Thinkcentre M80t Firmware Thinkcentre M820z All-in-one Thinkcentre M820z All-in-one Firmware Thinkcentre M90a Thinkcentre M90a Firmware Thinkcentre M90q Tiny Thinkcentre M90q Tiny Firmware Thinkcentre M90s Thinkcentre M90s Firmware Thinkcentre M90t Thinkcentre M90t Firmware Thinkcentre M920q Thinkcentre M920q Firmware Thinkcentre M920s Thinkcentre M920s Firmware Thinkcentre M920t Thinkcentre M920t Firmware Thinkcentre M920x Thinkcentre M920x Firmware Thinkcentre M920z All-in-one Thinkcentre M920z All-in-one Firmware Thinkedge Se30 Thinkedge Se30 Firmware Thinkstation P320 Workstation Thinkstation P320 Workstation Firmware Thinkstation P330 Tiny Workstation Thinkstation P330 Tiny Workstation Firmware Thinkstation P330 Workstation Thinkstation P330 Workstation 2nd Gen Thinkstation P330 Workstation 2nd Gen Firmware Thinkstation P330 Workstation Firmware Thinkstation P340 Tiny Workstation Thinkstation P340 Tiny Workstation Firmware Thinkstation P340 Workstation Thinkstation P340 Workstation Firmware Thinkstation P348 Workstation Thinkstation P348 Workstation Firmware Thinkstation P350 Workstation Thinkstation P350 Workstation Firmware Thinkstation P360 Workstation Thinkstation P360 Workstation Firmware Thinkstation P520 Workstation Thinkstation P520 Workstation Firmware Thinkstation P520c Workstation Thinkstation P520c Workstation Firmware Thinkstation P720 Workstation Thinkstation P720 Workstation Firmware Thinkstation P920 Workstation Thinkstation P920 Workstation Firmware V30a-22iml V30a-22iml Firmware V30a-24iml V30a-24iml Firmware V50a-22imb V50a-22imb Firmware V50a-24imb V50a-24imb Firmware V50s-07imb V50s-07imb Firmware V50t-13imb V50t-13imb Firmware V50t-13imh V50t-13imh Firmware V50t-13iob G2 V50t-13iob G2 Firmware V55t Gen 2 13acn V55t Gen 2 13acn Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-04T17:58:47.396Z

Reserved: 2023-10-03T17:36:49.034Z

Link: CVE-2023-45075

cve-icon Vulnrichment

Updated: 2024-08-02T20:14:19.819Z

cve-icon NVD

Status : Modified

Published: 2023-11-08T23:15:10.900

Modified: 2024-11-21T08:26:20.410

Link: CVE-2023-45075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses