Description
A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.
Published: 2023-11-08
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-141775

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-57418 A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.
History

Mon, 16 Sep 2024 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Mon, 16 Sep 2024 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1419

Subscriptions

Lenovo Thinkpad L13 Gen 2 Thinkpad L13 Gen 2 Firmware Thinkpad L13 Gen 3 Thinkpad L13 Gen 3 Firmware Thinkpad L13 Gen 4 Thinkpad L13 Gen 4 Firmware Thinkpad L13 Yoga Gen 2 Thinkpad L13 Yoga Gen 2 Firmware Thinkpad L13 Yoga Gen 3 Thinkpad L13 Yoga Gen 3 Firmware Thinkpad L13 Yoga Gen 4 Thinkpad L13 Yoga Gen 4 Firmware Thinkpad L14 Gen 3 Thinkpad L14 Gen 3 Firmware Thinkpad L14 Gen 4 Thinkpad L14 Gen 4 Firmware Thinkpad L15 Gen 3 Thinkpad L15 Gen 3 Firmware Thinkpad L15 Gen 4 Thinkpad L15 Gen 4 Firmware Thinkpad P14s Gen 3 Thinkpad P14s Gen 3 Firmware Thinkpad P16s Gen 1 Thinkpad P16s Gen 1 Firmware Thinkpad S2 Gen 8 Thinkpad S2 Gen 8 Firmware Thinkpad S2 Yoga Gen 6 Thinkpad S2 Yoga Gen 6 Firmware Thinkpad S2 Yoga Gen 7 Thinkpad S2 Yoga Gen 7 Firmware Thinkpad S2 Yoga Gen 8 Thinkpad S2 Yoga Gen 8 Firmware Thinkpad T14 Gen 3 Thinkpad T14 Gen 3 Firmware Thinkpad T14s Gen 3 Thinkpad T14s Gen 3 Firmware Thinkpad T16 Gen 1 Thinkpad T16 Gen 1 Firmware Thinkpad X13 Gen 3 Thinkpad X13 Gen 3 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-16T14:52:18.065Z

Reserved: 2023-09-19T20:53:37.522Z

Link: CVE-2023-5078

cve-icon Vulnrichment

Updated: 2024-08-02T07:44:53.770Z

cve-icon NVD

Status : Modified

Published: 2023-11-08T22:15:11.957

Modified: 2024-11-21T08:41:01.363

Link: CVE-2023-5078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses