MEDIUM
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to
Published Oct 24, 2023
4.4
MEDIUMCVSS 3.1
EPSS 0.21%
Description
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to
1.3.1.2
and
Lenovo Diagnostics versions prior to 4.45
that could allow a local user with administrative access to trigger a system crash.
Affected products
-
Affected
- < 4.45
-
Affected
- < 1.3.1.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Lenovo | Diagnostics | unaffected | Affected
|
| Lenovo | HardwareScanPlugin | unaffected | Affected
|
OR
- < 4.45.0
- < 1.3.1.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to Lenovo Diagnostics Application v4.45 or later.
Update the Lenovo HardwareScan Plugin to version 1.3.1.2 or later.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43056 Advisory
- https://support.lenovo.com/us/en/product_security/LEN-102365 Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-94532 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43056 | Advisory | |
| https://support.lenovo.com/us/en/product_security/LEN-102365 | Vendor Advisory | |
| https://support.lenovo.com/us/en/product_security/LEN-94532 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner lenovo
Published Oct 24, 2023
Updated Sep 17, 2024
Reserved Oct 26, 2022
Link CVE-2022-3698
CISA Vulnrichment
Updated Sep 11, 2024
Red Hat
No data
GitHub
No data