7.8
CVSSv3

CVE-2022-3431

Published: 09/10/2023 Updated: 14/10/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lenovo ideapad_creator_5-16ach6_firmware

lenovo ideapad_5_pro-16ihu6_firmware

lenovo ideapad_5_pro-16ach6_firmware

lenovo yoga_slim_7-13itl05_firmware

lenovo yoga_slim_7-13acn05_firmware

lenovo yoga_slim_7_pro_16arh7_firmware

lenovo yoga_slim_7_pro_16ach6_firmware

lenovo yoga_slim_7_carbon_13itl5_firmware

lenovo yoga_duet_7-13itl6-lte_firmware

lenovo yoga_duet_7-13itl6_firmware

lenovo yoga_duet_7-13iml05_firmware

lenovo thinkbook_plus_g3_iap_firmware

lenovo thinkbook_plus_g2_itg_firmware

lenovo thinkbook_16p_nx_arh_firmware

lenovo thinkbook_16_g4\\+_iap_firmware

lenovo thinkbook_16_g4\\+_ara_firmware

lenovo thinkbook_14_g4\\+_iap_firmware

lenovo thinkbook_14_g4\\+_ara_firmware

lenovo thinkbook_13x_itg_firmware

lenovo ideapad_slim_7_pro_16ach6_firmware

lenovo s540-15iml_firmware

lenovo slim_7_16arh7_firmware

lenovo ideapad_duet_3_10igl5_firmware

lenovo ideapad_5_pro_16arh7_firmware

lenovo d330-10igl_firmware