VulnerabilityModified
CVE-2022-4575
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.
MEDIUM 6.7EPSS 0.18%
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- lenovo/thinkpad 25 firmware · lenovo/thinkpad l560 firmware · lenovo/thinkpad p50 firmware · lenovo/thinkpad p50s firmware · lenovo/thinkpad p70 firmware · lenovo/thinkpad t470 firmware · lenovo/thinkpad t470s firmware · lenovo/thinkpad t560 firmware · lenovo/thinkpad x1 carbon 4th gen firmware · lenovo/thinkpad x1 yoga 1st gen firmware · lenovo/thinkpad x260 firmware · lenovo/thinkpad x270 firmware · lenovo/thinkpad yoga 260 firmware
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-106014Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-106014Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.