2023-01-23
|
CVE-2022-3430
|
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
|
D330\-10igl_firmware, Ideapad_5_pro_16arh7_firmware, Ideapad_5_pro_16iah7_firmware, Ideapad_duet_3_10igl5_firmware, Ideapad_slim_7\-14iil05_firmware, Ideapad_slim_7\-14itl05_firmware, Ideapad_slim_7\-15iil05_firmware, Slim_7\-14are05_firmware, Slim_7\-15imh05_firmware, Slim_7\-15itl05_firmware, Slim_7_16arh7_firmware, Thinkbook_13x_itg_firmware, Thinkbook_14_g2_are_firmware, Thinkbook_14_g2_itl_firmware, Thinkbook_14_g3_acl_firmware, Thinkbook_14_g3_itl_firmware, Thinkbook_14_g4\+_ara_firmware, Thinkbook_14_g4\+_iap_firmware, Thinkbook_14p_g3_arh_firmware, Thinkbook_14s_yoga_itl_firmware, Thinkbook_15_g2_are_firmware, Thinkbook_15_g2_itl_firmware, Thinkbook_15_g3_acl_firmware, Thinkbook_15_g3_itl_firmware, Thinkbook_15_gd_aba_firmware, Thinkbook_15p_g2_ith_firmware, Thinkbook_15p_imp_firmware, Thinkbook_16_g4\+_ara_firmware, Thinkbook_16_g4\+_iap_firmware, Thinkbook_16p_g3_arh_firmware, Thinkbook_16p_nx_arh_firmware, Thinkbook_plus_g2_itg_firmware, Thinkbook_plus_g3_iap_firmware, Yoga_creator_7\-15imh05_firmware, Yoga_duet_7\-13iml05_firmware, Yoga_duet_7\-13itl6\-Lte_firmware, Yoga_duet_7\-13itl6_firmware, Yoga_slim_7\-14are05_firmware, Yoga_slim_7\-14iil05_firmware, Yoga_slim_7\-14itl05_firmware, Yoga_slim_7\-15iil05_firmware, Yoga_slim_7\-15imh05_firmware, Yoga_slim_7\-15itl05_firmware, Yoga_slim_7_pro_16arh7_firmware
|
6.7
|
|
|
2023-10-09
|
CVE-2022-3431
|
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
|
D330\-10igl_firmware, Ideapad_5_pro\-16ach6_firmware, Ideapad_5_pro\-16ihu6_firmware, Ideapad_5_pro_16arh7_firmware, Ideapad_creator_5\-16ach6_firmware, Ideapad_duet_3_10igl5_firmware, Ideapad_slim_7_pro_16ach6_firmware, S540\-15iml_firmware, Slim_7_16arh7_firmware, Thinkbook_13x_itg_firmware, Thinkbook_14_g4\+_ara_firmware, Thinkbook_14_g4\+_iap_firmware, Thinkbook_16_g4\+_ara_firmware, Thinkbook_16_g4\+_iap_firmware, Thinkbook_16p_nx_arh_firmware, Thinkbook_plus_g2_itg_firmware, Thinkbook_plus_g3_iap_firmware, Yoga_duet_7\-13iml05_firmware, Yoga_duet_7\-13itl6\-Lte_firmware, Yoga_duet_7\-13itl6_firmware, Yoga_slim_7\-13acn05_firmware, Yoga_slim_7\-13itl05_firmware, Yoga_slim_7_carbon_13itl5_firmware, Yoga_slim_7_pro_16ach6_firmware, Yoga_slim_7_pro_16arh7_firmware
|
7.8
|
|
|
2023-11-08
|
CVE-2023-5075
|
A buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevated privileges to execute arbitrary code.
|
Ideapad_duet_3_10igl5_firmware
|
6.7
|
|
|