SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-40135

An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

MEDIUM 4.4EPSS 0.20%

Does this matter?

Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.

Description

An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

CVSS 3.1
4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
0.20% probability · 9th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
lenovo/ideacentre c5-14imb05 firmware · lenovo/thinkcentre e96z firmware · lenovo/ideacentre 3 07iab7 firmware · lenovo/ideacentre 3-07imb05 firmware · lenovo/ideacentre 5 14iab7 firmware · lenovo/ideacentre 5-14acn6 firmware · lenovo/ideacentre 5-14imb05 firmware · lenovo/ideacentre 5-14iob6 firmware · lenovo/ideacentre creator 5-14iob6 firmware · lenovo/ideacentre g5-14imb05 firmware · lenovo/ideacentre gaming 5 17acn7 firmware · lenovo/ideacentre gaming 5 17iab7 firmware · lenovo/ideacentre gaming 5-14acn6 firmware · lenovo/ideacentre gaming 5-14iob6 firmware · lenovo/legion c530-19icb firmware · lenovo/legion t5-26iob6 firmware · lenovo/legion t5-28icb05 firmware · lenovo/legion t530-28apr firmware · lenovo/legion t530-28icb firmware · lenovo/legion t7-34imz5 firmware · +40 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.