CVE-2022-40134
—CVSS 3.1
4.4 medium
EPSS
<1%p9
Published
()
Modified
Description
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
- Vendors
- lenovo
- Products
- ideacentre c5-14imb05 firmware, thinkcentre e96z firmware, ideacentre 3 07iab7 firmware, ideacentre 3-07imb05 firmware, ideacentre 5 14iab7 firmware, ideacentre 5-14acn6 firmware, ideacentre 5-14imb05 firmware, ideacentre 5-14iob6 firmware, ideacentre creator 5-14iob6 firmware, ideacentre g5-14imb05 firmware, ideacentre gaming 5 17acn7 firmware, ideacentre gaming 5 17iab7 firmware
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.