CVE-2022-4575
Summary
| CVE | CVE-2022-4575 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-30 15:15:00 UTC |
| Updated | 2023-11-08 00:24:00 UTC |
| Description | A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | Thinkpad 25 | - | All | All | All |
| Operating System | Lenovo | Thinkpad 25 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad L560 | - | All | All | All |
| Operating System | Lenovo | Thinkpad L560 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad P50 | - | All | All | All |
| Hardware | Lenovo | Thinkpad P50s | - | All | All | All |
| Operating System | Lenovo | Thinkpad P50s Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad P50 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad P70 | - | All | All | All |
| Operating System | Lenovo | Thinkpad P70 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad T470 | - | All | All | All |
| Hardware | Lenovo | Thinkpad T470s | - | All | All | All |
| Operating System | Lenovo | Thinkpad T470s Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad T470 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad T560 | - | All | All | All |
| Operating System | Lenovo | Thinkpad T560 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad X1 Carbon 4th Gen | - | All | All | All |
| Operating System | Lenovo | Thinkpad X1 Carbon 4th Gen Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad X1 Yoga 1st Gen | - | All | All | All |
| Operating System | Lenovo | Thinkpad X1 Yoga 1st Gen Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad X260 | - | All | All | All |
| Operating System | Lenovo | Thinkpad X260 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad X270 | - | All | All | All |
| Operating System | Lenovo | Thinkpad X270 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad Yoga 260 | - | All | All | All |
| Operating System | Lenovo | Thinkpad Yoga 260 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ThinkPad BIOS Vulnerabilities - Lenovo Support US | MISC | support.lenovo.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.