VulnerabilityModified
CVE-2023-4028
A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
MEDIUM 6.7EPSS 0.19%
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.19% probability · 9th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- lenovo/13w yoga firmware · lenovo/13w yoga gen 2 firmware · lenovo/ideapad 1-11ada05 firmware · lenovo/ideapad 1-11igl05 firmware · lenovo/ideapad 1-14ada05 firmware · lenovo/ideapad 1-14igl05 firmware · lenovo/flex 5-14alc05 firmware · lenovo/flex 5-14are05 firmware · lenovo/flex 5-14iil05 firmware · lenovo/flex 5-14itl05 firmware · lenovo/flex 5-15alc05 firmware · lenovo/flex 5-15iil05 firmware · lenovo/flex 5-15itl05 firmware · lenovo/ideapad flex 5 14abr8 firmware · lenovo/ideapad flex 5 14alc7 firmware · lenovo/ideapad flex 5 14iau7 firmware · lenovo/ideapad flex 5 14iru8 firmware · lenovo/ideapad flex 5 16abr8 firmware · lenovo/ideapad flex 5 16alc7 firmware · lenovo/ideapad flex 5 16iau7 firmware · +9 more
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-134879Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-134879Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.