CVE-2022-3430

MEDIUMCVSS 6.7/10EPSS 0.26%

Last modified

CVE-2022-3430 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.

Description

A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.26%

17.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoD330-10igl Firmware< g0cn11ww
LenovoIdeapad 5 Pro 16iah7 Firmware< j4cn33ww
LenovoIdeapad 5 Pro 16arh7 Firmware< j5cn27ww
LenovoIdeapad Duet 3 10igl5 Firmware< eqcn37ww
LenovoSlim 7 16arh7 Firmware< klcn15ww
LenovoThinkbook 15p Imp Firmware< f6cn25ww
LenovoSlim 7-14are05 Firmware< dmcn43ww
LenovoIdeapad Slim 7-14iil05 Firmware< dhcn35ww
LenovoIdeapad Slim 7-14itl05 Firmware< fbcn29ww
LenovoIdeapad Slim 7-15iil05 Firmware< dhcn35ww
LenovoSlim 7-15imh05 Firmware< dncn32ww
LenovoSlim 7-15itl05 Firmware< fbcn29ww
LenovoThinkbook 13x Itg Firmware< hlcn30ww
LenovoThinkbook 14 G2 Are Firmware< facn33ww
LenovoThinkbook 14 G2 Itl Firmware< f8cn52ww
LenovoThinkbook 14 G3 Acl Firmware< gqcn35ww_hfcn30ww
LenovoThinkbook 14 G3 Itl Firmware< hrcn13ww
LenovoThinkbook 14 G4\+ Ara Firmware< j6cn40ww
LenovoThinkbook 14 G4\+ Iap Firmware< hycn40ww
LenovoThinkbook 14p G3 Arh Firmware< k4cn31ww
LenovoThinkbook 14s Yoga Itl Firmware< fncn40ww
LenovoThinkbook 15 G2 Are Firmware< facn33ww
LenovoThinkbook 15 G2 Itl Firmware< f8cn52ww
LenovoThinkbook 15 G3 Acl Firmware< gqcn35ww_hfcn30ww
LenovoThinkbook 15 G3 Itl Firmware< hrcn13ww
LenovoThinkbook 15 Gd Aba Firmware< jpcn20ww
LenovoThinkbook 15p G2 Ith Firmware< hjcn31ww
LenovoThinkbook 16 G4\+ Ara Firmware< j6cn40ww
LenovoThinkbook 16 G4\+ Iap Firmware< hycn40ww
LenovoThinkbook 16p G3 Arh Firmware< kccn31ww
LenovoThinkbook 16p Nx Arh Firmware< kjcn27ww
LenovoThinkbook Plus G2 Itg Firmware< gycn31ww
LenovoThinkbook Plus G3 Iap Firmware< k6cn29ww
LenovoYoga Creator 7-15imh05 Firmware< dncn32ww
LenovoYoga Duet 7-13iml05 Firmware< ercn30ww
LenovoYoga Duet 7-13itl6 Firmware< gpcn24ww
LenovoYoga Duet 7-13itl6-Lte Firmware< gpcn24ww
LenovoYoga Slim 7 Pro 16arh7 Firmware< klcn15ww
LenovoYoga Slim 7-14are05 Firmware< dmcn43ww
LenovoYoga Slim 7-14iil05 Firmware< dmcn35ww
LenovoYoga Slim 7-14itl05 Firmware< fbcn29ww
LenovoYoga Slim 7-15iil05 Firmware< dhcn35ww
LenovoYoga Slim 7-15imh05 Firmware< dncn32ww
LenovoYoga Slim 7-15itl05 Firmware< fbcn29ww

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-3430?
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
How severe is CVE-2022-3430?
CVE-2022-3430 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.26% probability of exploitation in the next 30 days.
How do I fix CVE-2022-3430?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-3430?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST