SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-9062

In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

MEDIUM 6.8EPSS 0.51%

Does this matter?

Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.

Description

In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.51% probability · 42th percentile
CISA KEV
Not listed
Weakness
CWE-74
Affected
lenovo/e42-80 firmware · lenovo/e42-80 isk firmware · lenovo/e52-80 firmware · lenovo/e52-80 isk firmware · lenovo/miix 720-12ikb firmware · lenovo/v310-14ikb firmware · lenovo/v310-14isk firmware · lenovo/v310-15ikb firmware · lenovo/v310-15isk firmware · lenovo/v510-14ikb firmware · lenovo/v510-15ikb firmware · lenovo/thinkpad l380 firmware · lenovo/thinkpad e480 firmware · lenovo/thinkpad e580 firmware · lenovo/thinkpad l480 firmware · lenovo/thinkpad l580 firmware · lenovo/thinkpad p51 firmware · lenovo/thinkpad p51s firmware · lenovo/thinkpad p52 firmware · lenovo/thinkpad p52s firmware · +19 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.