ID

VAR-202306-0277


CVE

CVE-2022-48181


TITLE

Lenovo ThinkPad Buffer error vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202306-265

DESCRIPTION

An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code

Trust: 0.99

sources: NVD: CVE-2022-48181 // VULMON: CVE-2022-48181

AFFECTED PRODUCTS

vendor:lenovomodel:thinkcentre m70s gen 3scope:ltversion:m41kt3da

Trust: 1.0

vendor:lenovomodel:thinkcentre m75s gen 2scope:ltversion:m3akt4ca

Trust: 1.0

vendor:lenovomodel:thinkcentre m70t gen 3scope:ltversion:m41kt3da

Trust: 1.0

vendor:lenovomodel:thinkcentre m70sscope:ltversion:m2tkt52a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90q gen 2scope:ltversion:m3jkt37a

Trust: 1.0

vendor:lenovomodel:thinkcentre neo 50s gen 3scope:ltversion:m49kt21a

Trust: 1.0

vendor:lenovomodel:thinkstation p350scope:ltversion:s0akt39a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 5 27iah7scope:ltversion:o5rkt39a

Trust: 1.0

vendor:lenovomodel:v530s-07icbscope:ltversion:m22kt49a

Trust: 1.0

vendor:lenovomodel:thinkcentre neo 30a 22 gen 3scope:ltversion:o5nkt32a

Trust: 1.0

vendor:lenovomodel:legion r5-28imb05scope:ltversion:o4nkt1da

Trust: 1.0

vendor:lenovomodel:thinkcentre m75t gen 2scope:ltversion:m46kt30a

Trust: 1.0

vendor:lenovomodel:legion t5-26iob6scope:ltversion:o54kt22a

Trust: 1.0

vendor:lenovomodel:thinkstation p350 tinyscope:ltversion:m3jkt37a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90t gen 3scope:ltversion:m40kt3da

Trust: 1.0

vendor:lenovomodel:thinkcentre m600scope:ltversion:m00kt68a

Trust: 1.0

vendor:lenovomodel:v35s-07adascope:ltversion:m4mkt12a

Trust: 1.0

vendor:lenovomodel:v30a-24itlscope:ltversion:o5akt33

Trust: 1.0

vendor:lenovomodel:thinkcentre m60e tinyscope:ltversion:m3skt25a

Trust: 1.0

vendor:lenovomodel:thinkcentre neo 30a 27 gen 3scope:ltversion:o5nkt32a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90ascope:ltversion:m2rkt56a

Trust: 1.0

vendor:lenovomodel:legion c530-19icbscope:ltversion:o4bkt22a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90sscope:ltversion:m2tkt52a

Trust: 1.0

vendor:lenovomodel:ideacentre gaming 5 17acn7scope:ltversion:o5ekt24a

Trust: 1.0

vendor:lenovomodel:ideacentre 3 07ach7scope:ltversion:m4mkt12a

Trust: 1.0

vendor:lenovomodel:thinkcentre m920tscope:ltversion:m1ukt70a

Trust: 1.0

vendor:lenovomodel:thinkstation p320scope:ltversion:s06kt63a

Trust: 1.0

vendor:lenovomodel:thinkstation p340 tinyscope:ltversion:m2wkt59a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70q gen 3scope:ltversion:m43kt1ba

Trust: 1.0

vendor:lenovomodel:legion t7-34imz5scope:ltversion:o5fkt15a

Trust: 1.0

vendor:lenovomodel:thinkstation p330 gen 2scope:ltversion:m1vkt6fa

Trust: 1.0

vendor:lenovomodel:thinkcentre m90tscope:ltversion:m2tkt52a

Trust: 1.0

vendor:lenovomodel:ideacentre gaming 5-14iob6scope:ltversion:m3gkt3aa

Trust: 1.0

vendor:lenovomodel:thinkcentre m920xscope:ltversion:m1ukt70a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3-24imb05scope:ltversion:o5nkt32a

Trust: 1.0

vendor:lenovomodel:ideacentre 5 14iab7scope:ltversion:m42kt42a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3 27iap7scope:ltversion:o5nkt32a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90a pro gen 3scope:ltversion:m4hkt19a

Trust: 1.0

vendor:lenovomodel:ideacentre 5-14acn6scope:ltversion:o5ekt24a

Trust: 1.0

vendor:lenovomodel:ideacentre g5-14amr05scope:ltversion:o4zkt2aa

Trust: 1.0

vendor:lenovomodel:thinkcentre m920zscope:ltversion:m1mkt55a

Trust: 1.0

vendor:lenovomodel:thinkcentre m920sscope:ltversion:m1ukt70a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 5 24iah7scope:ltversion:o5rkt39a

Trust: 1.0

vendor:lenovomodel:legion t7-34imz5scope:ltversion:o4lkt20a

Trust: 1.0

vendor:lenovomodel:thinkcentre m720qscope:ltversion:m1ukt70a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90q tinyscope:ltversion:m2wkt59a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3-24itl6scope:ltversion:o5akt33

Trust: 1.0

vendor:lenovomodel:ideacentre g5-14imb05scope:ltversion:o4hkt3aa

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3 21itl7scope:ltversion:o5akt33

Trust: 1.0

vendor:lenovomodel:legion t7-34iaz7scope:ltversion:o5hkt2aa

Trust: 1.0

vendor:lenovomodel:ideacentre 3 07iab7scope:ltversion:m49kt21a

Trust: 1.0

vendor:lenovomodel:thinkstation p330 tinyscope:ltversion:m1ukt70a

Trust: 1.0

vendor:lenovomodel:thinkcentre m625qscope:ltversion:m1wkt50a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3-24alc6scope:ltversion:o5bkt25a

Trust: 1.0

vendor:lenovomodel:ideacentre mini 5-01imh05scope:ltversion:o4ekt19a

Trust: 1.0

vendor:lenovomodel:thinkstation p360scope:ltversion:s0ekt40a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3 22iap7scope:ltversion:o5nkt32a

Trust: 1.0

vendor:lenovomodel:thinkcentre m75s-1scope:ltversion:m2ckt4fa

Trust: 1.0

vendor:lenovomodel:ideacentre gaming 5-14acn6scope:ltversion:o5ekt24a

Trust: 1.0

vendor:lenovomodel:thinkcentre m720sscope:ltversion:m1ukt70a

Trust: 1.0

vendor:lenovomodel:thinkcentre neo 30a 24 gen 3scope:ltversion:o5nkt32a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90a gen 2scope:ltversion:m3lkt28a

Trust: 1.0

vendor:lenovomodel:v530s-07icrscope:ltversion:m1zkt40a

Trust: 1.0

vendor:lenovomodel:thinkcentre m80q gen 3scope:ltversion:m4gkt23a

Trust: 1.0

vendor:lenovomodel:legion t530-28icbscope:ltversion:o4bkt22a

Trust: 1.0

vendor:lenovomodel:thinkcentre m720tscope:ltversion:m1ukt70a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90q gen 3scope:ltversion:m4gkt23a

Trust: 1.0

vendor:lenovomodel:thinkcentre m80sscope:ltversion:m2tkt52a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70cscope:ltversion:m2vkt1ea

Trust: 1.0

vendor:lenovomodel:ideacentre 510s-07ickscope:ltversion:m1zkt40a

Trust: 1.0

vendor:lenovomodel:ideacentre 3-07ada05scope:ltversion:m4mkt12a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3-22imb05scope:ltversion:o5nkt32a

Trust: 1.0

vendor:lenovomodel:v50t-13imbscope:ltversion:o4hkt3aa

Trust: 1.0

vendor:lenovomodel:thinkcentre neo 50t gen 3scope:ltversion:m42kt42a

Trust: 1.0

vendor:lenovomodel:ideacentre 510s-07icbscope:ltversion:m22kt49a

Trust: 1.0

vendor:lenovomodel:thinkcentre m80t gen 3scope:ltversion:m40kt3da

Trust: 1.0

vendor:lenovomodel:ideacentre creator 5-14iob6scope:ltversion:m3gkt3aa

Trust: 1.0

vendor:lenovomodel:thinkcentre m725sscope:ltversion:m25kt63a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3 24iap7scope:ltversion:o5nkt32a

Trust: 1.0

vendor:lenovomodel:ideacentre 3-07ada05scope:ltversion:o4fkt35a

Trust: 1.0

vendor:lenovomodel:legion t5-28icb05scope:ltversion:o4bkt22a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70qscope:ltversion:m2wkt59a

Trust: 1.0

vendor:lenovomodel:thinkcentre m75s gen 2scope:ltversion:m46kt30a

Trust: 1.0

vendor:lenovomodel:thinkcentre m920qscope:ltversion:m1ukt70a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3-27itl6scope:ltversion:o5akt33

Trust: 1.0

vendor:lenovomodel:v50t-13iob g2scope:ltversion:m3gkt3aa

Trust: 1.0

vendor:lenovomodel:ideacentre 5-14iob6scope:ltversion:m3gkt3aa

Trust: 1.0

vendor:lenovomodel:thinkstation p360 tinyscope:ltversion:m4gkt23a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3-27imb05scope:ltversion:o5nkt32a

Trust: 1.0

vendor:lenovomodel:legion t5-28imb05scope:ltversion:o4nkt1da

Trust: 1.0

vendor:lenovomodel:thinkstation p340scope:ltversion:s08kt53a

Trust: 1.0

vendor:lenovomodel:thinkcentre m80tscope:ltversion:m2tkt52a

Trust: 1.0

vendor:lenovomodel:legion t5 26iab7scope:ltversion:o5lkt29a

Trust: 1.0

vendor:lenovomodel:thinkcentre m75nscope:ltversion:m33kt27a

Trust: 1.0

vendor:lenovomodel:v30a-22itlscope:ltversion:o5akt33

Trust: 1.0

vendor:lenovomodel:thinkstation p360scope:ltversion:s0ekt43a

Trust: 1.0

vendor:lenovomodel:ideacentre mini 5 01iaq7scope:ltversion:o53kt0ea

Trust: 1.0

vendor:lenovomodel:ideacentre c5-14imb05scope:ltversion:o4hkt3aa

Trust: 1.0

vendor:lenovomodel:thinkcentre m80qscope:ltversion:m2wkt59a

Trust: 1.0

vendor:lenovomodel:ideacentre 3-07imb05scope:ltversion:m2vkt1ea

Trust: 1.0

vendor:lenovomodel:thinkcentre m75t gen 2scope:ltversion:m3bkt2fa

Trust: 1.0

vendor:lenovomodel:ideacentre 5-14are05scope:ltversion:o4zkt2aa

Trust: 1.0

vendor:lenovomodel:v55t gen 2 13acnscope:ltversion:o5jkt23a

Trust: 1.0

vendor:lenovomodel:ideacentre 510s-07ickscope:ltversion:m30kt28a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70q gen 2scope:ltversion:m3jkt37a

Trust: 1.0

vendor:lenovomodel:thinkcentre m75t gen 2scope:ltversion:m3akt4ca

Trust: 1.0

vendor:lenovomodel:ideacentre 720-18aprscope:ltversion:m25kt63a

Trust: 1.0

vendor:lenovomodel:thinkstation p330scope:ltversion:m1vkt6fa

Trust: 1.0

vendor:lenovomodel:legion t5-26amr5scope:ltversion:o4mkt2da

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3-27alc6scope:ltversion:o5bkt25a

Trust: 1.0

vendor:lenovomodel:thinkcentre t540-15ama gscope:ltversion:m2ckt4fa

Trust: 1.0

vendor:lenovomodel:thinkcentre m80s gen 3scope:ltversion:m40kt3da

Trust: 1.0

vendor:lenovomodel:ideacentre 5-14imb05scope:ltversion:o4hkt3aa

Trust: 1.0

vendor:lenovomodel:thinkcentre m90s gen 3scope:ltversion:m40kt3da

Trust: 1.0

vendor:lenovomodel:thinkcentre m720escope:ltversion:m1zkt40a

Trust: 1.0

vendor:lenovomodel:ideacentre aio 3-22itl6scope:ltversion:o5akt33

Trust: 1.0

vendor:lenovomodel:ideacentre gaming 5 17iab7scope:ltversion:m42kt42a

Trust: 1.0

vendor:lenovomodel:thinkcentre m70tscope:ltversion:m2tkt52a

Trust: 1.0

vendor:lenovomodel:thinkcentre m90a gen 3scope:ltversion:m4ikt19a

Trust: 1.0

vendor:lenovomodel:v50s-07imbscope:ltversion:m2vkt1ea

Trust: 1.0

vendor:lenovomodel:thinkcentre neo 70t gen 3scope:ltversion:m40kt3da

Trust: 1.0

vendor:lenovomodel:thinkcentre m75s gen 2scope:ltversion:m3bkt2fa

Trust: 1.0

sources: NVD: CVE-2022-48181

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-48181
value: HIGH

Trust: 1.0

psirt@lenovo.com: CVE-2022-48181
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-202306-265
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2022-48181
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

psirt@lenovo.com: CVE-2022-48181
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: CNNVD: CNNVD-202306-265 // NVD: CVE-2022-48181 // NVD: CVE-2022-48181

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.0

sources: NVD: CVE-2022-48181

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202306-265

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202306-265

PATCH

title:Lenovo ThinkPad Buffer error vulnerability fixurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=241549

Trust: 0.6

sources: CNNVD: CNNVD-202306-265

EXTERNAL IDS

db:LENOVOid:LEN-124495

Trust: 1.7

db:NVDid:CVE-2022-48181

Trust: 1.7

db:CNNVDid:CNNVD-202306-265

Trust: 0.6

db:VULMONid:CVE-2022-48181

Trust: 0.1

sources: VULMON: CVE-2022-48181 // CNNVD: CNNVD-202306-265 // NVD: CVE-2022-48181

REFERENCES

url:https://support.lenovo.com/us/en/product_security/len-124495

Trust: 1.7

url:https://cxsecurity.com/cveshow/cve-2022-48181/

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2022-48181 // CNNVD: CNNVD-202306-265 // NVD: CVE-2022-48181

SOURCES

db:VULMONid:CVE-2022-48181
db:CNNVDid:CNNVD-202306-265
db:NVDid:CVE-2022-48181

LAST UPDATE DATE

2024-08-14T13:20:14.250000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2022-48181date:2023-06-06T00:00:00
db:CNNVDid:CNNVD-202306-265date:2023-06-14T00:00:00
db:NVDid:CVE-2022-48181date:2023-06-13T19:34:14.697

SOURCES RELEASE DATE

db:VULMONid:CVE-2022-48181date:2023-06-05T00:00:00
db:CNNVDid:CNNVD-202306-265date:2023-06-05T00:00:00
db:NVDid:CVE-2022-48181date:2023-06-05T22:15:11.383