ID

VAR-202301-2262


CVE

CVE-2022-40135


TITLE

plural  Lenovo  Out-of-bounds read vulnerability in model

Trust: 0.8

sources: JVNDB: JVNDB-2022-012877

DESCRIPTION

An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. plural Lenovo An out-of-bounds read vulnerability exists in the model.Information may be obtained

Trust: 1.71

sources: NVD: CVE-2022-40135 // JVNDB: JVNDB-2022-012877 // VULMON: CVE-2022-40135

AFFECTED PRODUCTS

vendor:lenovomodel:v55t-15apiscope:ltversion:o4dkt43a

Trust: 1.0

vendor:lenovomodel:legion t5-26iob6scope:ltversion:o54kt1da

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600tscope:ltversion:fwktbaa

Trust: 1.0

vendor:lenovomodel:thinkcentre m75nscope:ltversion:m33kt25a

Trust: 1.0

vendor:lenovomodel:v30a-22imlscope:ltversion:m37kt28a

Trust: 1.0

vendor:lenovomodel:v50t-13iob g2scope:ltversion:m3gkt33a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70cscope:ltversion:m2vkt1da

Trust: 1.0

vendor:lenovomodel:qt m410scope:ltversion:m16kt68a

Trust: 1.0

vendor:lenovomodel:thinkstation p340scope:ltversion:s08kt50a

Trust: 1.0

vendor:lenovomodel:thinksmart core \& controller full room kit\: microsoft teams roomsscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v520scope:ltversion:m16kt68a

Trust: 1.0

vendor:lenovomodel:thinksmart core \& controller kit\: zoom roomsscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m60e tinyscope:ltversion:m3skt21a

Trust: 1.0

vendor:lenovomodel:thinkcentre m75t gen 2scope:ltversion:m46kt2da

Trust: 1.0

vendor:lenovomodel:thinkstation p520cscope:ltversion:s03kt55a

Trust: 1.0

vendor:lenovomodel:ideacentre c5-14imb05scope:ltversion:o4hkt38a

Trust: 1.0

vendor:lenovomodel:thinkcentre m720tscope:ltversion:m1ukt67a

Trust: 1.0

vendor:lenovomodel:thinkcentre m818zscope:ltversion:m1ekt25a

Trust: 1.0

vendor:lenovomodel:v530-15icbscope:ltversion:m1ykt70a

Trust: 1.0

vendor:lenovomodel:thinksystem st58scope:ltversion:ite123e

Trust: 1.0

vendor:lenovomodel:thinkcentre m75q gen 2scope:ltversion:m47kt24a

Trust: 1.0

vendor:lenovomodel:ideacentre t540-15ama gscope:ltversion:m2ckt4da

Trust: 1.0

vendor:lenovomodel:v530-15arrscope:ltversion:o4dkt43a

Trust: 1.0

vendor:lenovomodel:thinkcentre m710sscope:ltversion:m16kt68a

Trust: 1.0

vendor:lenovomodel:thinkcentre m75s gen 2scope:ltversion:m46kt2da

Trust: 1.0

vendor:lenovomodel:v330-20icbscope:ltversion:m1qkt47a

Trust: 1.0

vendor:lenovomodel:thinksmart core \& controller kit\: microsoft teams roomsscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideacentre 510s-07ickscope:ltversion:m30kt26a

Trust: 1.0

vendor:lenovomodel:thinksmart core device for logitechscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:qt b415scope:ltversion:m16kt68a

Trust: 1.0

vendor:lenovomodel:v30a-24imlscope:ltversion:m37kt28a

Trust: 1.0

vendor:lenovomodel:thinkcentre m910xscope:ltversion:m1akt56a

Trust: 1.0

vendor:lenovomodel:ideacentre a340-22igmscope:ltversion:o51kt12a

Trust: 1.0

vendor:lenovomodel:ideacentre 5-14imb05scope:ltversion:o4hkt38a

Trust: 1.0

vendor:lenovomodel:thinkcentre m820zscope:ltversion:m1nkt58a

Trust: 1.0

vendor:lenovomodel:ideacentre 510a-15arrscope:ltversion:o4dkt43a

Trust: 1.0

vendor:lenovomodel:thinkcentre m920xscope:ltversion:m1ukt67a

Trust: 1.0

vendor:lenovomodel:ideacentre 510a-15ickscope:ltversion:o4kkt16a

Trust: 1.0

vendor:lenovomodel:ideacentre gaming 5 17iab7scope:ltversion:m42kt40a

Trust: 1.0

vendor:lenovomodel:thinkcentre m720sscope:ltversion:m1ukt67a

Trust: 1.0

vendor:lenovomodel:legion t5-28icb05scope:ltversion:o4bkt20a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70q gen 3scope:ltversion:m43kt16a

Trust: 1.0

vendor:lenovomodel:thinksmart core device for polyscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v35s-07adascope:ltversion:o4fkt29a

Trust: 1.0

vendor:lenovomodel:thinkcentre m920sscope:ltversion:m1ukt67a

Trust: 1.0

vendor:lenovomodel:ideacentre gaming 5-14iob6scope:ltversion:m3gkt33a

Trust: 1.0

vendor:lenovomodel:ideacentre t540-15ickscope:ltversion:o4kkt16a

Trust: 1.0

vendor:lenovomodel:thinkstation p330 tinyscope:ltversion:m1ukt67a

Trust: 1.0

vendor:lenovomodel:ideacentre gaming 5 17acn7scope:ltversion:o5ekt21a

Trust: 1.0

vendor:lenovomodel:stadia ggp-120scope:ltversion:s03kt55a

Trust: 1.0

vendor:lenovomodel:ideacentre 3 07iab7scope:ltversion:m49kt1da

Trust: 1.0

vendor:lenovomodel:ideacentre 510-15ickscope:ltversion:o4kkt16a

Trust: 1.0

vendor:lenovomodel:ideacentre g5-14amr05scope:ltversion:o4zkt29a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70qscope:ltversion:m2wkt57a

Trust: 1.0

vendor:lenovomodel:thinkcentre m610scope:ltversion:m1akt56a

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600qscope:ltversion:fwktbaa

Trust: 1.0

vendor:lenovomodel:thinkstation p620scope:ltversion:s07kt25a

Trust: 1.0

vendor:lenovomodel:thinkcentre m920qscope:ltversion:m1ukt67a

Trust: 1.0

vendor:lenovomodel:thinkcentre m75q-1scope:ltversion:m2fkt2da

Trust: 1.0

vendor:lenovomodel:thinkcentre m720escope:ltversion:m30kt26a

Trust: 1.0

vendor:lenovomodel:thinkcentre m810zscope:ltversion:m1ckt49a

Trust: 1.0

vendor:lenovomodel:thinkstation p520scope:ltversion:s03kt55a

Trust: 1.0

vendor:lenovomodel:thinkstation p310scope:ltversion:fwktbaa

Trust: 1.0

vendor:lenovomodel:qt m415scope:ltversion:m16kt68a

Trust: 1.0

vendor:lenovomodel:v530s-07icbscope:ltversion:m22kt48a

Trust: 1.0

vendor:lenovomodel:ideacentre 3-07ada05scope:ltversion:o4fkt29a

Trust: 1.0

vendor:lenovomodel:v50s-07imbscope:ltversion:m2vkt1da

Trust: 1.0

vendor:lenovomodel:v50t-13imbscope:ltversion:o4hkt38a

Trust: 1.0

vendor:lenovomodel:legion t530-28aprscope:ltversion:o4gkt16a

Trust: 1.0

vendor:lenovomodel:v530-15icrscope:ltversion:m2ykt31a

Trust: 1.0

vendor:lenovomodel:thinkstation p348scope:ltversion:m3kkt34a

Trust: 1.0

vendor:lenovomodel:thinkcentre m920tscope:ltversion:m1ukt67a

Trust: 1.0

vendor:lenovomodel:ideacentre g5-14imb05scope:ltversion:o4hkt38a

Trust: 1.0

vendor:lenovomodel:thinkcentre neo 50t gen 3scope:ltversion:m42kt40a

Trust: 1.0

vendor:lenovomodel:thinkcentre e96zscope:ltversion:m26kt22a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70ascope:ltversion:m2skt25a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90a gen2scope:ltversion:m3lkt26a

Trust: 1.0

vendor:lenovomodel:v50a-22imbscope:ltversion:m36kt28a

Trust: 1.0

vendor:lenovomodel:yoga a940-27icbscope:ltversion:o43kt43a

Trust: 1.0

vendor:lenovomodel:thinkstation p320 tinyscope:ltversion:m1akt56a

Trust: 1.0

vendor:lenovomodel:thinkcentre m910qscope:ltversion:m1akt56a

Trust: 1.0

vendor:lenovomodel:thinkcentre m80qscope:ltversion:m2wkt57a

Trust: 1.0

vendor:lenovomodel:v520sscope:ltversion:m16kt68a

Trust: 1.0

vendor:lenovomodel:thinkstation p350 tinyscope:ltversion:m3jkt34a

Trust: 1.0

vendor:lenovomodel:thinkcentre m710escope:ltversion:m1zkt38a

Trust: 1.0

vendor:lenovomodel:ideacentre 510s-07icbscope:ltversion:m22kt47a

Trust: 1.0

vendor:lenovomodel:v530-24icbscope:ltversion:m20kt52a

Trust: 1.0

vendor:lenovomodel:ideacentre 5-14iob6scope:ltversion:m3gkt33a

Trust: 1.0

vendor:lenovomodel:thinkcentre m710tscope:ltversion:m16kt68a

Trust: 1.0

vendor:lenovomodel:thinkcentre neo 50s gen 3scope:ltversion:m49kt1da

Trust: 1.0

vendor:lenovomodel:ideacentre 5-14are05scope:ltversion:o4zkt29a

Trust: 1.0

vendor:lenovomodel:thinkstation p340 tinyscope:ltversion:m2wkt57a

Trust: 1.0

vendor:lenovomodel:legion t530-28icbscope:ltversion:o4bkt20a

Trust: 1.0

vendor:lenovomodel:legion t7-34imz5scope:ltversion:o4lkt1ea

Trust: 1.0

vendor:lenovomodel:thinksmart hub teamsscope:ltversion:m2xkt20a

Trust: 1.0

vendor:lenovomodel:thinkcentre m75s-1scope:ltversion:m2ckt4da

Trust: 1.0

vendor:lenovomodel:thinkcentre m715qscope:ltversion:m11kt54a

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600sscope:ltversion:fwktbaa

Trust: 1.0

vendor:lenovomodel:thinkcentre m710qscope:ltversion:m1akt56a

Trust: 1.0

vendor:lenovomodel:thinkstation p318scope:ltversion:m1akt56a

Trust: 1.0

vendor:lenovomodel:ideacentre a340-24igmscope:ltversion:o51kt12a

Trust: 1.0

vendor:lenovomodel:qitian a815scope:ltversion:m1rkt38a

Trust: 1.0

vendor:lenovomodel:thinksmart hub zoomscope:ltversion:m2xkt20a

Trust: 1.0

vendor:lenovomodel:thinkstation p350scope:lteversion:s0akt34a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70t gen 3scope:ltversion:m41kt2da

Trust: 1.0

vendor:lenovomodel:ideacentre gaming 5-14acn6scope:ltversion:o5ekt21a

Trust: 1.0

vendor:lenovomodel:yangtian afq150scope:ltversion:fwktbaa

Trust: 1.0

vendor:lenovomodel:thinkcentre m70a gen 2scope:ltversion:m3nkt20a

Trust: 1.0

vendor:lenovomodel:thinksmart core \& controller full room kit\: zoom roomsscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m715tscope:ltversion:m2ckt4da

Trust: 1.0

vendor:lenovomodel:v530s-07icrscope:ltversion:m30kt26a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70q gen 2scope:ltversion:m2wkt57a

Trust: 1.0

vendor:lenovomodel:thinkcentre e75 t\/sscope:ltversion:m16kt68a

Trust: 1.0

vendor:lenovomodel:ideacentre 5-14acn6scope:ltversion:o5ekt21a

Trust: 1.0

vendor:lenovomodel:ideacentre 720-18aprscope:ltversion:m25kt61a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90ascope:ltversion:m2rkt52a

Trust: 1.0

vendor:lenovomodel:v50a-24imbscope:ltversion:m36kt28a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90q gen 2scope:ltversion:m3jkt34a

Trust: 1.0

vendor:lenovomodel:legion c530-19icbscope:ltversion:o4bkt20a

Trust: 1.0

vendor:lenovomodel:v55t-15arescope:ltversion:o4dkt43a

Trust: 1.0

vendor:lenovomodel:yta8900fscope:ltversion:fwktbaa

Trust: 1.0

vendor:lenovomodel:v55t gen 2 13acnscope:ltversion:o5jkt20a

Trust: 1.0

vendor:lenovomodel:thinkcentre m630escope:ltversion:m28kt37a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70s gen 3scope:ltversion:m41kt2da

Trust: 1.0

vendor:lenovomodel:thinkcentre m910sscope:ltversion:m1akt56a

Trust: 1.0

vendor:lenovomodel:ideacentre 3-07imb05scope:ltversion:m2vkt1da

Trust: 1.0

vendor:lenovomodel:ideacentre 5 14iab7scope:ltversion:m42kt40a

Trust: 1.0

vendor:lenovomodel:thinkcentre m625qscope:ltversion:m1wkt45a

Trust: 1.0

vendor:lenovomodel:ideacentre creator 5-14iob6scope:lteversion:m3gkt33a

Trust: 1.0

vendor:lenovomodel:thinkcentre m720qscope:ltversion:m1ukt67a

Trust: 1.0

vendor:lenovomodel:thinksmart core device\: zoom roomsscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v530-22icbscope:ltversion:m20kt52a

Trust: 1.0

vendor:lenovomodel:thinkedge se30scope:ltversion:m3fkt29a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90q tinyscope:ltversion:m2wkt57a

Trust: 1.0

vendor:lenovomodel:thinksystem st50scope:ltversion:ite123e

Trust: 1.0

vendor:lenovomodel:thinkcentre m725sscope:ltversion:m25kt61a

Trust: 1.0

vendor:lenovomodel:thinkcentre m910tscope:ltversion:m1akt56a

Trust: 1.0

vendor:lenovomodel:v540-24iwlscope:ltversion:m29kt39a

Trust: 1.0

vendor:lenovomodel:ideacentre 5-14imb05scope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre g5-14imb05scope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 5 14iab7scope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre creator 5-14iob6scope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkcentre e96zscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 5-14acn6scope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre c5-14imb05scope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 5-14iob6scope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 3-07imb05scope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 3 07iab7scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-012877 // NVD: CVE-2022-40135

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2022-40135
value: MEDIUM

Trust: 1.0

psirt@lenovo.com: CVE-2022-40135
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2022-012877
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202301-2382
value: MEDIUM

Trust: 0.6

NVD:
baseSeverity: MEDIUM
baseScore: 4.4
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 0.8
impactScore: 3.6
version: 3.1

Trust: 2.0

OTHER: JVNDB-2022-012877
baseSeverity: MEDIUM
baseScore: 4.4
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-012877 // NVD: CVE-2022-40135 // NVD: CVE-2022-40135 // CNNVD: CNNVD-202301-2382

PROBLEMTYPE DATA

problemtype:CWE-125

Trust: 1.0

problemtype:Out-of-bounds read (CWE-125) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-012877 // NVD: CVE-2022-40135

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202301-2382

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202301-2382

CONFIGURATIONS

sources: NVD: CVE-2022-40135

PATCH

title:LEN-94953url:https://support.lenovo.com/us/en/product_security/len-94953

Trust: 0.8

title:Lenovo Desktops Buffer error vulnerability fixurl:http://123.124.177.30/web/xxk/bdxqbyid.tag?id=225282

Trust: 0.6

title: - url:https://github.com/live-hack-cve/cve-2022-40135

Trust: 0.1

sources: VULMON: CVE-2022-40135 // JVNDB: JVNDB-2022-012877 // CNNVD: CNNVD-202301-2382

EXTERNAL IDS

db:NVDid:CVE-2022-40135

Trust: 3.3

db:LENOVOid:LEN-94953

Trust: 1.7

db:JVNDBid:JVNDB-2022-012877

Trust: 0.8

db:CNNVDid:CNNVD-202301-2382

Trust: 0.6

db:VULMONid:CVE-2022-40135

Trust: 0.1

sources: VULMON: CVE-2022-40135 // JVNDB: JVNDB-2022-012877 // NVD: CVE-2022-40135 // CNNVD: CNNVD-202301-2382

REFERENCES

url:https://support.lenovo.com/us/en/product_security/len-94953

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-40135

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-40135/

Trust: 0.6

url:https://github.com/live-hack-cve/cve-2022-40135

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2022-40135 // JVNDB: JVNDB-2022-012877 // NVD: CVE-2022-40135 // CNNVD: CNNVD-202301-2382

SOURCES

db:VULMONid:CVE-2022-40135
db:JVNDBid:JVNDB-2022-012877
db:NVDid:CVE-2022-40135
db:CNNVDid:CNNVD-202301-2382

LAST UPDATE DATE

2023-12-18T13:06:17.844000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2022-40135date:2023-01-31T00:00:00
db:JVNDBid:JVNDB-2022-012877date:2023-09-04T01:53:00
db:NVDid:CVE-2022-40135date:2023-02-14T14:28:34.773
db:CNNVDid:CNNVD-202301-2382date:2023-02-15T00:00:00

SOURCES RELEASE DATE

db:VULMONid:CVE-2022-40135date:2023-01-30T00:00:00
db:JVNDBid:JVNDB-2022-012877date:2023-09-04T00:00:00
db:NVDid:CVE-2022-40135date:2023-01-30T22:15:12.257
db:CNNVDid:CNNVD-202301-2382date:2023-01-30T00:00:00