ID

VAR-202204-1314


CVE

CVE-2022-0354


TITLE

Lenovo  of  System Update  Code injection vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2022-008720

DESCRIPTION

A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update package released before 2022-02-25 that displays a command prompt window. Lenovo of System Update There is a code injection vulnerability in.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.8

sources: NVD: CVE-2022-0354 // JVNDB: JVNDB-2022-008720 // VULHUB: VHN-413305 // VULMON: CVE-2022-0354

AFFECTED PRODUCTS

vendor:lenovomodel:system updatescope:ltversion:2022-02-25

Trust: 1.0

vendor:lenovomodel:system updatescope:eqversion:2022-02-25

Trust: 0.8

vendor:lenovomodel:system updatescope:eqversion: -

Trust: 0.8

vendor:lenovomodel:system updatescope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-008720 // NVD: CVE-2022-0354

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-0354
value: HIGH

Trust: 1.0

psirt@lenovo.com: CVE-2022-0354
value: HIGH

Trust: 1.0

NVD: CVE-2022-0354
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202204-4279
value: HIGH

Trust: 0.6

VULHUB: VHN-413305
value: HIGH

Trust: 0.1

VULMON: CVE-2022-0354
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2022-0354
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-413305
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2022-0354
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

psirt@lenovo.com: CVE-2022-0354
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.3
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2022-0354
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-413305 // VULMON: CVE-2022-0354 // JVNDB: JVNDB-2022-008720 // CNNVD: CNNVD-202204-4279 // NVD: CVE-2022-0354 // NVD: CVE-2022-0354

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Code injection (CWE-94) [NVD evaluation ]

Trust: 0.8

problemtype:CWE-94

Trust: 0.1

sources: VULHUB: VHN-413305 // JVNDB: JVNDB-2022-008720 // NVD: CVE-2022-0354

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202204-4279

TYPE

code injection

Trust: 0.6

sources: CNNVD: CNNVD-202204-4279

PATCH

title:Lenovo Vantage Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=190714

Trust: 0.6

sources: CNNVD: CNNVD-202204-4279

EXTERNAL IDS

db:NVDid:CVE-2022-0354

Trust: 3.4

db:LENOVOid:LEN-76673

Trust: 2.6

db:JVNDBid:JVNDB-2022-008720

Trust: 0.8

db:CNNVDid:CNNVD-202204-4279

Trust: 0.6

db:VULHUBid:VHN-413305

Trust: 0.1

db:VULMONid:CVE-2022-0354

Trust: 0.1

sources: VULHUB: VHN-413305 // VULMON: CVE-2022-0354 // JVNDB: JVNDB-2022-008720 // CNNVD: CNNVD-202204-4279 // NVD: CVE-2022-0354

REFERENCES

url:https://www.infosec.tirol/cve-2022-0354/

Trust: 2.6

url:https://support.lenovo.com/us/en/product_security/len-76673

Trust: 2.6

url:https://nvd.nist.gov/vuln/detail/cve-2022-0354

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-0354/

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/94.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-413305 // VULMON: CVE-2022-0354 // JVNDB: JVNDB-2022-008720 // CNNVD: CNNVD-202204-4279 // NVD: CVE-2022-0354

SOURCES

db:VULHUBid:VHN-413305
db:VULMONid:CVE-2022-0354
db:JVNDBid:JVNDB-2022-008720
db:CNNVDid:CNNVD-202204-4279
db:NVDid:CVE-2022-0354

LAST UPDATE DATE

2024-11-23T22:32:53.198000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-413305date:2022-05-04T00:00:00
db:VULMONid:CVE-2022-0354date:2022-05-04T00:00:00
db:JVNDBid:JVNDB-2022-008720date:2023-07-28T08:06:00
db:CNNVDid:CNNVD-202204-4279date:2022-05-05T00:00:00
db:NVDid:CVE-2022-0354date:2024-11-21T06:38:26.727

SOURCES RELEASE DATE

db:VULHUBid:VHN-413305date:2022-04-22T00:00:00
db:VULMONid:CVE-2022-0354date:2022-04-22T00:00:00
db:JVNDBid:JVNDB-2022-008720date:2023-07-28T00:00:00
db:CNNVDid:CNNVD-202204-4279date:2022-04-22T00:00:00
db:NVDid:CVE-2022-0354date:2022-04-22T21:15:10.187