7.8
CVSSv3

CVE-2022-3431

Published: 09/10/2023 Updated: 14/10/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lenovo ideapad creator 5-16ach6 firmware

lenovo ideapad 5 pro-16ihu6 firmware

lenovo ideapad 5 pro-16ach6 firmware

lenovo yoga slim 7-13itl05 firmware

lenovo yoga slim 7-13acn05 firmware

lenovo yoga slim 7 pro 16arh7 firmware

lenovo yoga slim 7 pro 16ach6 firmware

lenovo yoga slim 7 carbon 13itl5 firmware

lenovo yoga duet 7-13itl6-lte firmware

lenovo yoga duet 7-13itl6 firmware

lenovo yoga duet 7-13iml05 firmware

lenovo thinkbook plus g3 iap firmware

lenovo thinkbook plus g2 itg firmware

lenovo thinkbook 16p nx arh firmware

lenovo thinkbook 16 g4+ iap firmware

lenovo thinkbook 16 g4+ ara firmware

lenovo thinkbook 14 g4+ iap firmware

lenovo thinkbook 14 g4+ ara firmware

lenovo thinkbook 13x itg firmware

lenovo ideapad slim 7 pro 16ach6 firmware

lenovo s540-15iml firmware

lenovo slim 7 16arh7 firmware

lenovo ideapad duet 3 10igl5 firmware

lenovo ideapad 5 pro 16arh7 firmware

lenovo d330-10igl firmware