CVE-2022-48189
—CVSS 3.1
6.7 medium
EPSS
<1%p9
Published
()
Modified
Description
An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.
- Vendors
- lenovo
- Products
- thinkpad e14 firmware, thinkpad e14 gen 2 firmware, thinkpad e14 gen 4 firmware, thinkpad e15 firmware, thinkpad e15 gen 2 firmware, thinkpad e15 gen 4 firmware, thinkpad e490 firmware, thinkpad e490s firmware, thinkpad e590 firmware, thinkpad l13 gen 3 firmware, thinkpad l13 yoga gen 3 firmware, thinkpad l14 firmware
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.