CVE-2022-3431

HIGHCVSS 7.8/10EPSS 0.21%

Last modified

CVE-2022-3431 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.21%

10.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoIdeapad Creator 5-16ach6 Firmware< gscn34ww
LenovoIdeapad 5 Pro-16ihu6 Firmware< grcn22ww
LenovoIdeapad 5 Pro-16ach6 Firmware< gscn34ww
LenovoYoga Slim 7-13itl05 Firmware< f7cn39ww
LenovoYoga Slim 7-13acn05 Firmware< ghcn28ww
LenovoYoga Slim 7 Pro 16arh7 Firmware< klcn15ww
LenovoYoga Slim 7 Pro 16ach6 Firmware< hucn16ww
LenovoYoga Slim 7 Carbon 13itl5 Firmware< f7cn39ww
LenovoYoga Duet 7-13itl6-Lte Firmware< gpcn24ww
LenovoYoga Duet 7-13itl6 Firmware< gpcn24ww
LenovoYoga Duet 7-13iml05 Firmware< ercn30ww
LenovoThinkbook Plus G3 Iap Firmware< k6cn29ww
LenovoThinkbook Plus G2 Itg Firmware< gycn31ww
LenovoThinkbook 16p Nx Arh Firmware< kjcn27ww
LenovoThinkbook 16 G4\+ Iap Firmware< hycn40ww
LenovoThinkbook 16 G4\+ Ara Firmware< j6cn40ww
LenovoThinkbook 14 G4\+ Iap Firmware< hycn40ww
LenovoThinkbook 14 G4\+ Ara Firmware< j6cn40ww
LenovoThinkbook 13x Itg Firmware< hlcn30ww
LenovoIdeapad Slim 7 Pro 16ach6 Firmware< hucn16ww
LenovoS540-15iml Firmware< cncn22ww
LenovoSlim 7 16arh7 Firmware< klcn15ww
LenovoIdeapad Duet 3 10igl5 Firmware< eqcn37ww
LenovoIdeapad 5 Pro 16arh7 Firmware< j4cn33ww
LenovoD330-10igl Firmware< g0cn11ww

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-3431?
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
How severe is CVE-2022-3431?
CVE-2022-3431 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2022-3431?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-3431?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST