CVE-2018-9062

MEDIUMCVSS 6.8/10EPSS 0.51%

Last modified

CVE-2018-9062 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.

Description

In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

Metrics

CVSS 3.1
6.8/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.51%

39.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoE42-80 Firmware< 2wcn40ww
LenovoE42-80 Isk Firmware< 0zcn48ww
LenovoE52-80 Firmware< 2wcn40ww
LenovoE52-80 Isk Firmware< 0zcn48ww
LenovoMiix 720-12ikb Firmware< 3scn68ww
LenovoV310-14ikb Firmware< 2wcn40ww
LenovoV310-14isk Firmware< 0zcn48ww
LenovoV310-15ikb Firmware< 2wcn40ww
LenovoV310-15isk Firmware< 0zcn48ww
LenovoV510-14ikb Firmware< 2wcn40ww
LenovoV510-15ikb Firmware< 2wcn40ww
LenovoThinkpad L380 Firmware< r0ret28w
LenovoThinkpad E480 Firmware< r0pet47w
LenovoThinkpad E580 Firmware< r0pet47w
LenovoThinkpad L480 Firmware< r0qet47w
LenovoThinkpad L580 Firmware< r0qet47w
LenovoThinkpad P51 Firmware< n1uet71w
LenovoThinkpad P51s Firmware< n1vet45w
LenovoThinkpad P52 Firmware< n2cet28w
LenovoThinkpad P52s Firmware< n27et27w
LenovoThinkpad P71 Firmware< n1tet50w
LenovoThinkpad P72 Firmware< n2cet28w
LenovoThinkpad T25 Firmware< n1qet77w
LenovoThinkpad T470 Firmware< n1qet77w
LenovoThinkpad T470p Firmware< r0fet44w
LenovoThinkpad T470s Firmware< n1wet49w
LenovoThinkpad T480 Firmware< n24et41w
LenovoThinkpad T480s Firmware< n22et48w
LenovoThinkpad T570 Firmware< n1vet45w
LenovoThinkpad T580 Firmware< n27et27w
LenovoThinkpad X380 Yoga Firmware< r0set29w
LenovoThinkpad Yoga 11e Firmware< r0vet23w
LenovoThinkpad Yoga 370 Firmware< r0het48w
LenovoThinkpad S1 Firmware< r0het48w
LenovoThinkpad X1 Carbon Firmware< n1met49w
LenovoThinkpad X1 Carbon Firmware< n23et52w
LenovoThinkpad X1 Tablet Firmware< n1oet45w
LenovoThinkpad X1 Tablet Firmware< n1zet69w
LenovoThinkpad X1 Yoga Firmware< n1net42w
LenovoThinkpad X1 Yoga Firmware< n25et38w
LenovoThinkpad X270 Firmware< r0iet53w
LenovoThinkpad X280 Firmware< n20et33w

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-9062?
In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.
How severe is CVE-2018-9062?
CVE-2018-9062 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.51% probability of exploitation in the next 30 days.
How do I fix CVE-2018-9062?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-9062?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST