ID

VAR-202301-2330


CVE

CVE-2022-34888


TITLE

plural  Lenovo  Improper Comparison Vulnerability in Products

Trust: 0.8

sources: JVNDB: JVNDB-2022-012565

DESCRIPTION

The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect. plural Lenovo An improper comparison vulnerability exists in the product.Information may be obtained

Trust: 1.71

sources: NVD: CVE-2022-34888 // JVNDB: JVNDB-2022-012565 // VULMON: CVE-2022-34888

AFFECTED PRODUCTS

vendor:lenovomodel:thinksystem sr850scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile hx7521scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx2321scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx2720-escope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile mx3530-hscope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinksystem st250 v2scope:ltversion:1.96_tgbt34x

Trust: 1.0

vendor:lenovomodel:thinksystem sd530scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinksystem st250scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile vx3720scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinksystem sr258 v2scope:ltversion:1.96_tgbt34x

Trust: 1.0

vendor:lenovomodel:thinksystem sr650 v2scope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinkagile hx3721scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile hx3321scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx1021scope:ltversion:3.60_tei386m

Trust: 1.0

vendor:lenovomodel:thinksystem st550scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinksystem sr665scope:ltversion:4.10_d8bt38l

Trust: 1.0

vendor:lenovomodel:thinksystem sr150scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinksystem sr250scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile mx3531-fscope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinkagile hx3376scope:ltversion:4.10_d8bt38l

Trust: 1.0

vendor:lenovomodel:thinkagile vx 2u4nscope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile mx3530 fscope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinkagile vx7520 nscope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile mx3531 hscope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinksystem sr670 v2scope:ltversion:2.00_tgbt36o

Trust: 1.0

vendor:lenovomodel:thinkagile vx7531scope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinkagile vx5530scope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinkagile vx3320scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinksystem sn850scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile mx1021scope:ltversion:3.60_tei386m

Trust: 1.0

vendor:lenovomodel:thinksystem sr645scope:ltversion:4.10_d8bt38l

Trust: 1.0

vendor:lenovomodel:thinksystem st258 v2scope:ltversion:1.96_tgbt34x

Trust: 1.0

vendor:lenovomodel:thinkagile vx 4uscope:ltversion:2.50_psi346l

Trust: 1.0

vendor:lenovomodel:thinkagile hx5521-cscope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinksystem sn550 v2scope:ltversion:2.00_tgbt36o

Trust: 1.0

vendor:lenovomodel:thinkagile vx7520scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinksystem st650 v2scope:ltversion:2.00_tgbt36o

Trust: 1.0

vendor:lenovomodel:thinkagile mx3330-hscope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinksystem sr590scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile mx3331-fscope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinksystem sr630scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile vx1320scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinksystem sr850pscope:ltversion:3.60_tei386m

Trust: 1.0

vendor:lenovomodel:thinksystem sr158scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile vx3520-gscope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile vx7320 nscope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx5520scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx7820scope:ltversion:2.50_psi346l

Trust: 1.0

vendor:lenovomodel:thinksystem sn550scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinksystem sr650scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinksystem sr860scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile hx3375scope:ltversion:4.10_d8bt38l

Trust: 1.0

vendor:lenovomodel:thinkagile vx2320scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile vx5520scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinksystem sd650 v2scope:ltversion:2.00_tgbt36o

Trust: 1.0

vendor:lenovomodel:thinksystem sr570scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx2320-escope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx1520-rscope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx3320scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx3521-gscope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinksystem sr550scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile vx7820scope:ltversion:2.50_psi346l

Trust: 1.0

vendor:lenovomodel:thinkagile hx7821scope:ltversion:2.50_psi346l

Trust: 1.0

vendor:lenovomodel:thinkagile hx3520-gscope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinksystem sr950scope:ltversion:2.50_psi346l

Trust: 1.0

vendor:lenovomodel:thinkagile mx1020scope:lteversion:3.60_tei386m

Trust: 1.0

vendor:lenovomodel:thinkagile hx1320scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx5521scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile vx3530-gscope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinkagile hx1321scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinksystem sd650-n v2scope:ltversion:2.00_tgbt36o

Trust: 1.0

vendor:lenovomodel:thinksystem sr670scope:ltversion:3.60_tei386m

Trust: 1.0

vendor:lenovomodel:thinkagile mx3331-hscope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinksystem sr860 v2scope:ltversion:2.00_tgbt36o

Trust: 1.0

vendor:lenovomodel:thinksystem st258scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinksystem st658 v2scope:ltversion:2.00_tgbt36o

Trust: 1.0

vendor:lenovomodel:thinksystem sr850 v2scope:ltversion:2.00_tgbt36o

Trust: 1.0

vendor:lenovomodel:thinkagile hx3720scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkstation p920scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx5520-cscope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx enclosure certified nodescope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile vx7330scope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinkagile vx7530scope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinksystem sr250 v2scope:ltversion:1.96_tgbt34x

Trust: 1.0

vendor:lenovomodel:thinksystem sd630 v2scope:ltversion:2.00_tgbt36o

Trust: 1.0

vendor:lenovomodel:thinkagile vx3331scope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinksystem sr530scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile vx 1se certified nodescope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinksystem sr630 v2scope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinkagile hx1521-rscope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile mx3330-fscope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinksystem sd650 dwcscope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile vx2330scope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinkagile vx3330scope:ltversion:1.80_afbt20n

Trust: 1.0

vendor:lenovomodel:thinkedge se450scope:ltversion:1.10_usx304w

Trust: 1.0

vendor:lenovomodel:thinksystem se350scope:ltversion:3.60_tei386m

Trust: 1.0

vendor:lenovomodel:thinksystem sr258scope:ltversion:5.20_tei3c8m

Trust: 1.0

vendor:lenovomodel:thinkagile hx7520scope:ltversion:8.40-cdi394n

Trust: 1.0

vendor:lenovomodel:thinkagile hx1520-rscope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkagile hx1521-rscope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkagile hx1321scope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkagile hx2320-escope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkagile hx2720-escope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkagile vx3331scope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkagile hx enclosure certified nodescope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkagile hx1021scope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkagile hx1320scope: - version: -

Trust: 0.8

vendor:lenovomodel:thinkagile hx2321scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-012565 // NVD: CVE-2022-34888

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-34888
value: MEDIUM

Trust: 1.0

psirt@lenovo.com: CVE-2022-34888
value: LOW

Trust: 1.0

NVD: CVE-2022-34888
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202301-2376
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2022-34888
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.1

Trust: 1.0

psirt@lenovo.com: CVE-2022-34888
baseSeverity: LOW
baseScore: 2.7
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: LOW
exploitabilityScore: 1.2
impactScore: 1.4
version: 3.1

Trust: 1.0

NVD: CVE-2022-34888
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-012565 // CNNVD: CNNVD-202301-2376 // NVD: CVE-2022-34888 // NVD: CVE-2022-34888

PROBLEMTYPE DATA

problemtype:CWE-697

Trust: 1.0

problemtype:CWE-184

Trust: 1.0

problemtype:Inappropriate comparison (CWE-697) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-012565 // NVD: CVE-2022-34888

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202301-2376

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202301-2376

PATCH

title:LEN-87734url:https://support.lenovo.com/us/en/product_security/LEN-87734

Trust: 0.8

title:Lenovo XClarity Controller Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=223622

Trust: 0.6

title: - url:https://github.com/Live-Hack-CVE/CVE-2022-34888

Trust: 0.1

sources: VULMON: CVE-2022-34888 // JVNDB: JVNDB-2022-012565 // CNNVD: CNNVD-202301-2376

EXTERNAL IDS

db:NVDid:CVE-2022-34888

Trust: 3.3

db:LENOVOid:LEN-87734

Trust: 1.7

db:JVNDBid:JVNDB-2022-012565

Trust: 0.8

db:CNNVDid:CNNVD-202301-2376

Trust: 0.6

db:VULMONid:CVE-2022-34888

Trust: 0.1

sources: VULMON: CVE-2022-34888 // JVNDB: JVNDB-2022-012565 // CNNVD: CNNVD-202301-2376 // NVD: CVE-2022-34888

REFERENCES

url:https://support.lenovo.com/us/en/product_security/len-87734

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-34888

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-34888/

Trust: 0.6

url:https://github.com/live-hack-cve/cve-2022-34888

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2022-34888 // JVNDB: JVNDB-2022-012565 // CNNVD: CNNVD-202301-2376 // NVD: CVE-2022-34888

SOURCES

db:VULMONid:CVE-2022-34888
db:JVNDBid:JVNDB-2022-012565
db:CNNVDid:CNNVD-202301-2376
db:NVDid:CVE-2022-34888

LAST UPDATE DATE

2024-08-14T15:00:33.556000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2022-34888date:2023-01-31T00:00:00
db:JVNDBid:JVNDB-2022-012565date:2023-08-31T02:42:00
db:CNNVDid:CNNVD-202301-2376date:2023-02-09T00:00:00
db:NVDid:CVE-2022-34888date:2023-02-08T22:18:21.590

SOURCES RELEASE DATE

db:VULMONid:CVE-2022-34888date:2023-01-30T00:00:00
db:JVNDBid:JVNDB-2022-012565date:2023-08-31T00:00:00
db:CNNVDid:CNNVD-202301-2376date:2023-01-30T00:00:00
db:NVDid:CVE-2022-34888date:2023-01-30T22:15:11.960