A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface
Published Aug 23, 2023
6.7
MEDIUMCVSS 3.1
EPSS 0.17%
Description
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.
Affected products
-
Affected
- various
Configuration 1
- < jkcn34ww
Running on/with
- n/a
Configuration 2
- < kkcn15ww
Running on/with
- n/a
Configuration 3
- < jkcn34ww
Running on/with
- n/a
Configuration 4
- < kkcn15ww
Running on/with
- n/a
Configuration 5
- < htcn31ww
Running on/with
- n/a
Configuration 6
- < htcn31ww
Running on/with
- n/a
Configuration 7
- < jkcn34ww
Running on/with
- n/a
Configuration 8
- < jkcn34ww
Running on/with
- n/a
Configuration 9
- < jkcn34ww
Running on/with
- n/a
Configuration 10
- < dvcn28ww
Running on/with
- n/a
Configuration 11
- < emcn56ww
Running on/with
- n/a
Configuration 12
- < ggcn51ww
Running on/with
- n/a
Configuration 13
- < jbcn27ww
Running on/with
- n/a
Configuration 14
- < fhcn70ww
Running on/with
- n/a
Configuration 15
- < ejcn30ww
Running on/with
- n/a
Configuration 16
- < gfcn29ww
Configuration 17
- < j2cn49ww
Running on/with
- n/a
Configuration 18
- < j2cn49ww
Running on/with
- n/a
Configuration 19
- < j2cn49ww
Running on/with
- n/a
Configuration 20
- < j2cn49ww
Running on/with
- n/a
Configuration 21
- < h1cn52ww
Running on/with
- n/a
Configuration 22
- < h1cn52ww
Running on/with
- n/a
Configuration 23
- < efcn58ww
Running on/with
- n/a
Configuration 24
- < efcn58ww
Running on/with
- n/a
Configuration 25
- < g8cn22ww
Running on/with
- n/a
Configuration 26
- < h1cn52ww
Running on/with
- n/a
Configuration 27
- < h1cn52ww
Running on/with
- n/a
Configuration 28
- < efcn58ww
Running on/with
- n/a
Configuration 29
- < efcn58ww
Running on/with
- n/a
Configuration 30
- < h1cn52ww
Running on/with
- n/a
Configuration 31
- < h1cn52ww
Running on/with
- n/a
Configuration 32
- < efcn58ww
Running on/with
- n/a
Configuration 33
- < efcn58ww
Running on/with
- n/a
Configuration 34
- < k1cn40ww
Running on/with
- n/a
Configuration 35
- < h1cn52ww
Running on/with
- n/a
Configuration 36
- < ggcn51ww
Running on/with
- n/a
Configuration 37
- < jkcn34ww
Running on/with
- n/a
Configuration 38
- < jhcn28ww
Running on/with
- n/a
Configuration 39
- < k2cn34ww
Running on/with
- n/a
Configuration 40
- < hmcn41ww
Running on/with
- n/a
Configuration 41
- < j3cn49ww
Running on/with
- n/a
Configuration 42
- < f6cn26ww
Running on/with
- n/a
Configuration 43
- < htcn31ww
Running on/with
- n/a
Configuration 44
- < jkcn34ww
Running on/with
- n/a
Configuration 45
- < htcn31ww
Running on/with
- n/a
Configuration 46
- < jkcn34ww
Running on/with
- n/a
Configuration 47
- < jkcn34ww
Running on/with
- n/a
Configuration 48
- < fzcn26ww
Running on/with
- n/a
Configuration 49
- < fjcn74ww
Running on/with
- n/a
Configuration 50
- < escn56ww
Running on/with
- n/a
Configuration 51
- < hjcn32ww
Running on/with
- n/a
Configuration 52
- < dxcn44ww
Running on/with
- n/a
Configuration 53
- < ggcn51ww
Running on/with
- n/a
Configuration 54
- < dvcn28ww
Configuration 55
- < dxcn44ww
Running on/with
- n/a
Configuration 56
- < ggcn51ww
Running on/with
- n/a
Configuration 57
- < dvcn28ww
Configuration 58
- < ggcn51ww
Running on/with
- n/a
Configuration 59
- < emcn56ww
Configuration 60
- < j1cn35ww
Running on/with
- n/a
Configuration 61
- < j1cn35ww
Running on/with
- n/a
Configuration 62
- < j1cn35ww
Running on/with
- n/a
Configuration 63
- < f5cn59ww
Running on/with
- n/a
Configuration 64
- < f5cn59ww
Running on/with
- n/a
Configuration 65
- < hncn42ww
Running on/with
- n/a
Configuration 66
- < k2cn34ww
Running on/with
- n/a
Configuration 67
- < krcn14ww
Running on/with
- n/a
Configuration 68
- < jhcn28ww
Running on/with
- n/a
Configuration 69
- < fjcn74ww
Running on/with
- n/a
Configuration 70
- < fjcn74ww
Running on/with
- n/a
Configuration 71
- < fjcn74ww
Running on/with
- n/a
Configuration 72
- < hmcn41ww
Running on/with
- n/a
Configuration 73
- < j3cn49ww
Running on/with
- n/a
Configuration 74
- < escn56ww
Running on/with
- n/a
Configuration 75
- < dvcn28ww
Running on/with
- n/a
Configuration 76
- < emcn56ww
Running on/with
- n/a
Configuration 77
- < dxcn44ww
Running on/with
- n/a
Configuration 78
- < gccn32ww
Running on/with
- n/a
Configuration 79
- < ggcn51ww
Running on/with
- n/a
Configuration 80
- < emcn56ww
Running on/with
- n/a
Configuration 81
- < dxcn44ww
Running on/with
- n/a
Configuration 82
- < gccn32ww
Running on/with
- n/a
Configuration 83
- < ggcn51ww
Running on/with
- n/a
Configuration 84
- < dxcn44ww
Running on/with
- n/a
Configuration 85
- < dpcn58ww
Running on/with
- n/a
Configuration 86
- < egcn40ww
Running on/with
- n/a
Configuration 87
- < egcn40ww
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-103710.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43102 Advisory
- https://support.lenovo.com/us/en/product_security/LEN-103710 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43102 | Advisory | |
| https://support.lenovo.com/us/en/product_security/LEN-103710 | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data