CVE Vulnerabilities

CVE-2022-3728

Improper Physical Access Control

Published: Oct 09, 2023 | Modified: Oct 12, 2023
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.

Weakness

The product is designed with access restricted to certain information, but it does not sufficiently protect against an unauthorized actor with physical access to these areas.

Affected Software

Name Vendor Start Version End Version
Thinkpad_t14s_gen_3_firmware Lenovo * 1.30 (excluding)

Potential Mitigations

References