A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable
Published Jan 23, 2023
6.7
MEDIUMCVSS 3.1
EPSS 0.26%
Description
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Affected products
-
- Version variousStatusaffectedConstraints-
- Version
Configuration 1
- < g0cn11ww
Running on/with
- n/a
Configuration 2
- < j4cn33ww
Running on/with
- n/a
Configuration 3
- < j5cn27ww
Running on/with
- n/a
Configuration 4
- < eqcn37ww
Running on/with
- n/a
Configuration 5
- < klcn15ww
Running on/with
- n/a
Configuration 6
- < f6cn25ww
Running on/with
- n/a
Configuration 7
- < dmcn43ww
Running on/with
- n/a
Configuration 8
- < dhcn35ww
Running on/with
- n/a
Configuration 9
- < fbcn29ww
Running on/with
- n/a
Configuration 10
- < dhcn35ww
Running on/with
- n/a
Configuration 11
- < dncn32ww
Running on/with
- n/a
Configuration 12
- < fbcn29ww
Running on/with
- n/a
Configuration 13
- < hlcn30ww
Running on/with
- n/a
Configuration 14
- < facn33ww
Running on/with
- n/a
Configuration 15
- < f8cn52ww
Running on/with
- n/a
Configuration 16
- < gqcn35ww_hfcn30ww
Running on/with
- n/a
Configuration 17
- < hrcn13ww
Running on/with
- n/a
Configuration 18
- < j6cn40ww
Running on/with
- n/a
Configuration 19
- < hycn40ww
Running on/with
- n/a
Configuration 20
- < k4cn31ww
Running on/with
- n/a
Configuration 21
- < fncn40ww
Running on/with
- n/a
Configuration 22
- < facn33ww
Running on/with
- n/a
Configuration 23
- < f8cn52ww
Running on/with
- n/a
Configuration 24
- < gqcn35ww_hfcn30ww
Running on/with
- n/a
Configuration 25
- < hrcn13ww
Running on/with
- n/a
Configuration 26
- < jpcn20ww
Running on/with
- n/a
Configuration 27
- < hjcn31ww
Running on/with
- n/a
Configuration 28
- < j6cn40ww
Running on/with
- n/a
Configuration 29
- < hycn40ww
Running on/with
- n/a
Configuration 30
- < kccn31ww
Running on/with
- n/a
Configuration 31
- < kjcn27ww
Running on/with
- n/a
Configuration 32
- < gycn31ww
Running on/with
- n/a
Configuration 33
- < k6cn29ww
Running on/with
- n/a
Configuration 34
- < dncn32ww
Running on/with
- n/a
Configuration 35
- < ercn30ww
Running on/with
- n/a
Configuration 36
- < gpcn24ww
Running on/with
- n/a
Configuration 37
- < gpcn24ww
Running on/with
- n/a
Configuration 38
- < klcn15ww
Running on/with
- n/a
Configuration 39
- < dmcn43ww
Running on/with
- n/a
Configuration 40
- < dmcn35ww
Running on/with
- n/a
Configuration 41
- < fbcn29ww
Running on/with
- n/a
Configuration 42
- < dhcn35ww
Running on/with
- n/a
Configuration 43
- < dncn32ww
Running on/with
- n/a
Configuration 44
- < fbcn29ww
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update system firmware to the version (or newer) indicated for your model in the product Impact section of LEN-94952
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42806 Advisory
- https://support.lenovo.com/us/en/product_security/LEN-94952 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42806 | Advisory | |
| https://support.lenovo.com/us/en/product_security/LEN-94952 | Vendor Advisory |
Change history (0)
No recorded changes yet.