CVE Vulnerabilities

CVE-2022-4574

Published: Oct 30, 2023 | Modified: Nov 08, 2023
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.  

Affected Software

Name Vendor Start Version End Version
Thinkpad_x13_yoga_gen_2_firmware Lenovo * 1.40 (excluding)

References