VulnerabilityModified
CVE-2022-40134
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
MEDIUM 4.4EPSS 0.20%
Does this matter?
Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.
Description
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.20% probability · 9th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- lenovo/ideacentre c5-14imb05 firmware · lenovo/thinkcentre e96z firmware · lenovo/ideacentre 3 07iab7 firmware · lenovo/ideacentre 3-07imb05 firmware · lenovo/ideacentre 5 14iab7 firmware · lenovo/ideacentre 5-14acn6 firmware · lenovo/ideacentre 5-14imb05 firmware · lenovo/ideacentre 5-14iob6 firmware · lenovo/ideacentre creator 5-14iob6 firmware · lenovo/ideacentre g5-14imb05 firmware · lenovo/ideacentre gaming 5 17acn7 firmware · lenovo/ideacentre gaming 5 17iab7 firmware · lenovo/ideacentre gaming 5-14acn6 firmware · lenovo/ideacentre gaming 5-14iob6 firmware · lenovo/legion c530-19icb firmware · lenovo/legion t5-26iob6 firmware · lenovo/legion t5-28icb05 firmware · lenovo/legion t530-28apr firmware · lenovo/legion t530-28icb firmware · lenovo/legion t7-34imz5 firmware · +40 more
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-94953Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-94953Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.