CVE-2022-40134
Last modified
CVE-2022-40134 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Ideacentre C5-14imb05 Firmware | o4hkt38a |
| Lenovo | Thinkcentre E96z Firmware | m26kt22a |
| Lenovo | Ideacentre 3 07iab7 Firmware | m49kt1da |
| Lenovo | Ideacentre 3-07imb05 Firmware | m2vkt1da |
| Lenovo | Ideacentre 5 14iab7 Firmware | m42kt40a |
| Lenovo | Ideacentre 5-14acn6 Firmware | o5ekt21a |
| Lenovo | Ideacentre 5-14imb05 Firmware | o4hkt38a |
| Lenovo | Ideacentre 5-14iob6 Firmware | m3gkt33a |
| Lenovo | Ideacentre Creator 5-14iob6 Firmware | m3gkt33a |
| Lenovo | Ideacentre G5-14imb05 Firmware | o4hkt38a |
| Lenovo | Ideacentre Gaming 5 17acn7 Firmware | o5ekt21a |
| Lenovo | Ideacentre Gaming 5 17iab7 Firmware | m42kt40a |
| Lenovo | Ideacentre Gaming 5-14acn6 Firmware | o5ekt21a |
| Lenovo | Ideacentre Gaming 5-14iob6 Firmware | m3gkt33a |
| Lenovo | Legion C530-19icb Firmware | o4bkt20a |
| Lenovo | Legion T5-26iob6 Firmware | o54kt1da |
| Lenovo | Legion T5-28icb05 Firmware | o4bkt20a |
| Lenovo | Legion T530-28apr Firmware | o4gkt16a |
| Lenovo | Legion T530-28icb Firmware | o4bkt20a |
| Lenovo | Legion T7-34imz5 Firmware | o4lkt1ea |
| Lenovo | Thinkcentre M60e Tiny Firmware | o5fkt14a |
| Lenovo | Thinkcentre M625q Firmware | m3skt21a |
| Lenovo | Thinkcentre M630e Firmware | m1wkt45a |
| Lenovo | Thinkcentre M70a Firmware | m28kt37a |
| Lenovo | Thinkcentre M70a Gen 2 Firmware | m2skt25a |
| Lenovo | Thinkcentre M70c Firmware | m3nkt20a |
| Lenovo | Thinkcentre M70q Firmware | m2vkt1da |
| Lenovo | Thinkcentre M70q Gen 2 Firmware | m2wkt57a |
| Lenovo | Thinkcentre M70q Gen 3 Firmware | m3jkt34a |
| Lenovo | Thinkcentre M70s Firmware | m43kt16a |
| Lenovo | Thinkcentre M70s Gen 3 Firmware | m2tkt50a |
| Lenovo | Thinkcentre M70t Firmware | m41kt2da |
| Lenovo | Thinkcentre M70t Gen 3 Firmware | m2tkt50a |
| Lenovo | Thinkcentre M710e Firmware | m41kt2da |
| Lenovo | Thinkcentre M710q Firmware | m1zkt38a |
| Lenovo | Thinkcentre M710s Firmware | m1akt56a |
| Lenovo | Thinkcentre M710t Firmware | m16kt68a |
| Lenovo | Thinkcentre M715q Firmware | m16kt68a |
| Lenovo | Thinkcentre M720e Firmware | m11kt54a |
| Lenovo | Thinkcentre M75n Firmware | m30kt26a |
| Lenovo | Thinkcentre M75q Gen 2 Firmware | m33kt25a |
| Lenovo | Thinkcentre M75t Gen 2 Firmware | m47kt24a |
| Lenovo | Thinkcentre M80q Firmware | m46kt2da |
| Lenovo | Thinkcentre M80s Firmware | m2wkt57a |
| Lenovo | Thinkcentre M80s Firmware | m2tkt50a |
| Lenovo | Thinkcentre M80t Firmware | m2tkt50a |
| Lenovo | Thinkcentre M80t Firmware | m1ckt49a |
| Lenovo | Thinkcentre M810z All-In-One Firmware | m1ekt25a |
| Lenovo | Thinkcentre M818z Firmware | m1nkt58a |
| Lenovo | Thinkcentre M820z All-In-One Firmware | m2rkt52a |
Showing 50 of 337 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/us/en/product_security/LEN-94953Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-94953Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-40134?
How severe is CVE-2022-40134?
How do I fix CVE-2022-40134?
Are you affected by CVE-2022-40134?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
