SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-48189

An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.

MEDIUM 6.7EPSS 0.19%

Does this matter?

Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.

Description

An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.19% probability · 9th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
lenovo/thinkpad e14 firmware · lenovo/thinkpad e14 gen 2 firmware · lenovo/thinkpad e14 gen 4 firmware · lenovo/thinkpad e15 firmware · lenovo/thinkpad e15 gen 2 firmware · lenovo/thinkpad e15 gen 4 firmware · lenovo/thinkpad e490 firmware · lenovo/thinkpad e490s firmware · lenovo/thinkpad e590 firmware · lenovo/thinkpad l13 gen 3 firmware · lenovo/thinkpad l13 yoga gen 3 firmware · lenovo/thinkpad l14 firmware · lenovo/thinkpad l15 firmware · lenovo/thinkpad l15 gen 2 firmware · lenovo/thinkpad l15 gen 3 firmware · lenovo/thinkpad l490 firmware · lenovo/thinkpad l590 firmware · lenovo/thinkpad p1 gen 2 firmware · lenovo/thinkpad p1 gen 3 firmware · lenovo/thinkpad p1 gen 4 firmware · +40 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.