lenovo thinkpad_11e_firmware 输入验证不恰当

admin 2023-11-30 08:05:13 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
lenovo thinkpad_11e_firmware 输入验证不恰当

CVE编号

CVE-2022-1107

利用情况

暂无

补丁情况

N/A

披露时间

2022-04-23
漏洞描述
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://support.lenovo.com/us/en/product_security/LEN-84943
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
系统 lenovo thinkpad_11e_firmware * Up to (excluding) n15et78w
运行在以下环境
系统 lenovo thinkpad_11e_yoga_firmware * Up to (excluding) n15et78w
运行在以下环境
系统 lenovo thinkpad_helix_firmware * Up to (excluding) n17eta8w
运行在以下环境
系统 lenovo thinkpad_l560_firmware * Up to (excluding) n1het85w
运行在以下环境
系统 lenovo thinkpad_l570_firmware * Up to (excluding) n1xet65w
运行在以下环境
系统 lenovo thinkpad_p50s_firmware * Up to (excluding) n1ket46w
运行在以下环境
系统 lenovo thinkpad_p51s_firmware * Up to (excluding) n1vet50w
运行在以下环境
系统 lenovo thinkpad_p52s_firmware * Up to (excluding) n27et36w
运行在以下环境
系统 lenovo thinkpad_s540_firmware * Up to (excluding) gpet80ww
运行在以下环境
系统 lenovo thinkpad_t550_firmware * Up to (excluding) n11et50w
运行在以下环境
系统 lenovo thinkpad_t560_firmware * Up to (excluding) n1ket46w
运行在以下环境
系统 lenovo thinkpad_t570_firmware * Up to (excluding) n1vet50w
运行在以下环境
系统 lenovo thinkpad_t580_firmware * Up to (excluding) n27et36w
运行在以下环境
系统 lenovo thinkpad_w540_firmware * Up to (excluding) gnet92ww
运行在以下环境
系统 lenovo thinkpad_w541_firmware * Up to (excluding) gnet92ww
运行在以下环境
系统 lenovo thinkpad_w550s_firmware * Up to (excluding) n11et50w
运行在以下环境
系统 lenovo thinkpad_x1_carbon_3rd_gen_firmware * Up to (excluding) n14et52w
运行在以下环境
系统 lenovo thinkpad_x1_carbon_4th_gen_firmware * Up to (excluding) n1fet70w
运行在以下环境
系统 lenovo thinkpad_x1_carbon_5th_gen_kabylake_firmware * Up to (excluding) n1met55w
运行在以下环境
系统 lenovo thinkpad_x1_carbon_5th_gen_skylake_firmware * Up to (excluding) n1met55w
运行在以下环境
系统 lenovo thinkpad_x1_tablet_gen_1_firmware * Up to (excluding) n1let86w
运行在以下环境
系统 lenovo thinkpad_x1_tablet_gen_2_firmware * Up to (excluding) n1oet50w
运行在以下环境
系统 lenovo thinkpad_x1_yoga_firmware * Up to (excluding) n1fet70w
运行在以下环境
系统 lenovo thinkpad_x1_yoga_gen_2_firmware * Up to (excluding) n1net47w
运行在以下环境
系统 lenovo thinkpad_x1_yoga_gen_3_firmware * Up to (excluding) n25et50w
运行在以下环境
系统 lenovo thinkpad_x250_firmware * Up to (excluding) n10et58w
运行在以下环境
系统 lenovo thinkpad_x280_firmware * Up to (excluding) n20et44w
运行在以下环境
系统 lenovo thinkpad_x390_firmware * Up to (excluding) n2let60w
运行在以下环境
系统 lenovo thinkpad_yoga_15_firmware * Up to (excluding) n19et61w
运行在以下环境
系统 lenovo thinkpad_yoga_260_firmware * Up to (excluding) n1get98w
运行在以下环境
硬件 lenovo thinkpad_11e - -
运行在以下环境
硬件 lenovo thinkpad_11e_yoga - -
运行在以下环境
硬件 lenovo thinkpad_helix - -
运行在以下环境
硬件 lenovo thinkpad_l560 - -
运行在以下环境
硬件 lenovo thinkpad_l570 - -
运行在以下环境
硬件 lenovo thinkpad_p50s - -
运行在以下环境
硬件 lenovo thinkpad_p51s - -
运行在以下环境
硬件 lenovo thinkpad_p52s - -
运行在以下环境
硬件 lenovo thinkpad_s540 - -
运行在以下环境
硬件 lenovo thinkpad_t550 - -
运行在以下环境
硬件 lenovo thinkpad_t560 - -
运行在以下环境
硬件 lenovo thinkpad_t570 - -
运行在以下环境
硬件 lenovo thinkpad_t580 - -
运行在以下环境
硬件 lenovo thinkpad_w540 - -
运行在以下环境
硬件 lenovo thinkpad_w541 - -
运行在以下环境
硬件 lenovo thinkpad_w550s - -
运行在以下环境
硬件 lenovo thinkpad_x1_carbon_3rd_gen - -
运行在以下环境
硬件 lenovo thinkpad_x1_carbon_4th_gen - -
运行在以下环境
硬件 lenovo thinkpad_x1_carbon_5th_gen_kabylake - -
运行在以下环境
硬件 lenovo thinkpad_x1_carbon_5th_gen_skylake - -
运行在以下环境
硬件 lenovo thinkpad_x1_tablet_gen_1 - -
运行在以下环境
硬件 lenovo thinkpad_x1_tablet_gen_2 - -
运行在以下环境
硬件 lenovo thinkpad_x1_yoga - -
运行在以下环境
硬件 lenovo thinkpad_x1_yoga_gen_2 - -
运行在以下环境
硬件 lenovo thinkpad_x1_yoga_gen_3 - -
运行在以下环境
硬件 lenovo thinkpad_x250 - -
运行在以下环境
硬件 lenovo thinkpad_x280 - -
运行在以下环境
硬件 lenovo thinkpad_x390 - -
运行在以下环境
硬件 lenovo thinkpad_yoga_15 - -
运行在以下环境
硬件 lenovo thinkpad_yoga_260 - -
CVSS3评分 7.8
  • 攻击路径 本地
  • 攻击复杂度 低
  • 权限要求 低
  • 影响范围 未更改
  • 用户交互 无
  • 可用性 高
  • 保密性 高
  • 完整性 高
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-ID 漏洞类型
CWE-20 输入验证不恰当
CWE-269 特权管理不恰当
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0