Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
High
Attack Vector
Local
0

CVE-2022-4575

Disclosure Date: October 30, 2023
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
6.7 Medium
Impact Score:
5.9
Exploitability Score:
0.8
Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • lenovo

Products

  • thinkpad 25 firmware,
  • thinkpad l560 firmware,
  • thinkpad p50 firmware,
  • thinkpad p50s firmware,
  • thinkpad p70 firmware,
  • thinkpad t470 firmware,
  • thinkpad t470s firmware,
  • thinkpad t560 firmware,
  • thinkpad x1 carbon 4th gen firmware,
  • thinkpad x1 yoga 1st gen firmware,
  • thinkpad x260 firmware,
  • thinkpad x270 firmware,
  • thinkpad yoga 260 firmware

Additional Info

Technical Analysis