CVE-2022-3431

Summary

CVECVE-2022-3431
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2023-10-09 19:15:00 UTC
Updated2023-10-14 02:23:00 UTC
DescriptionA potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Risk And Classification

Problem Types: CWE-276

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Lenovo D330-10igl - All All All
Operating System Lenovo D330-10igl Firmware All All All All
Hardware Lenovo Ideapad 5 Pro-16ach6 - All All All
Operating System Lenovo Ideapad 5 Pro-16ach6 Firmware All All All All
Hardware Lenovo Ideapad 5 Pro-16ihu6 - All All All
Operating System Lenovo Ideapad 5 Pro-16ihu6 Firmware All All All All
Hardware Lenovo Ideapad 5 Pro 16arh7 - All All All
Operating System Lenovo Ideapad 5 Pro 16arh7 Firmware All All All All
Hardware Lenovo Ideapad Creator 5-16ach6 - All All All
Operating System Lenovo Ideapad Creator 5-16ach6 Firmware All All All All
Hardware Lenovo Ideapad Duet 3 10igl5 - All All All
Operating System Lenovo Ideapad Duet 3 10igl5 Firmware All All All All
Hardware Lenovo Ideapad Slim 7 Pro 16ach6 - All All All
Operating System Lenovo Ideapad Slim 7 Pro 16ach6 Firmware All All All All
Hardware Lenovo S540-15iml - All All All
Operating System Lenovo S540-15iml Firmware All All All All
Hardware Lenovo Slim 7 16arh7 - All All All
Operating System Lenovo Slim 7 16arh7 Firmware All All All All
Hardware Lenovo Thinkbook 13x Itg - All All All
Operating System Lenovo Thinkbook 13x Itg Firmware All All All All
Hardware Lenovo Thinkbook 14 G4 Ara - All All All
Operating System Lenovo Thinkbook 14 G4 Ara Firmware All All All All
Hardware Lenovo Thinkbook 14 G4 Iap - All All All
Operating System Lenovo Thinkbook 14 G4 Iap Firmware All All All All
Hardware Lenovo Thinkbook 16p Nx Arh - All All All
Operating System Lenovo Thinkbook 16p Nx Arh Firmware All All All All
Hardware Lenovo Thinkbook 16 G4 Ara - All All All
Operating System Lenovo Thinkbook 16 G4 Ara Firmware All All All All
Hardware Lenovo Thinkbook 16 G4 Iap - All All All
Operating System Lenovo Thinkbook 16 G4 Iap Firmware All All All All
Hardware Lenovo Thinkbook Plus G2 Itg - All All All
Operating System Lenovo Thinkbook Plus G2 Itg Firmware All All All All
Hardware Lenovo Thinkbook Plus G3 Iap - All All All
Operating System Lenovo Thinkbook Plus G3 Iap Firmware All All All All
Hardware Lenovo Yoga Duet 7-13iml05 - All All All
Operating System Lenovo Yoga Duet 7-13iml05 Firmware All All All All
Hardware Lenovo Yoga Duet 7-13itl6 - All All All
Hardware Lenovo Yoga Duet 7-13itl6-lte - All All All
Operating System Lenovo Yoga Duet 7-13itl6-lte Firmware All All All All
Operating System Lenovo Yoga Duet 7-13itl6 Firmware All All All All
Hardware Lenovo Yoga Slim 7-13acn05 - All All All
Operating System Lenovo Yoga Slim 7-13acn05 Firmware All All All All
Hardware Lenovo Yoga Slim 7-13itl05 - All All All
Operating System Lenovo Yoga Slim 7-13itl05 Firmware All All All All
Hardware Lenovo Yoga Slim 7 Carbon 13itl5 - All All All
Operating System Lenovo Yoga Slim 7 Carbon 13itl5 Firmware All All All All
Hardware Lenovo Yoga Slim 7 Pro 16ach6 - All All All
Operating System Lenovo Yoga Slim 7 Pro 16ach6 Firmware All All All All
Hardware Lenovo Yoga Slim 7 Pro 16arh7 - All All All
Operating System Lenovo Yoga Slim 7 Pro 16arh7 Firmware All All All All

References

ReferenceSourceLinkTags
Lenovo Notebook BIOS Vulnerabilities - Lenovo Support US MISC support.lenovo.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report