CVE-2022-40135

MEDIUMCVSS 4.4/10EPSS 0.20%

Last modified

CVE-2022-40135 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.

Description

An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

Metrics

CVSS 3.1
4.4/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.20%

9.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoIdeacentre C5-14imb05 Firmware< o4hkt38a
LenovoThinkcentre E96z Firmware< m26kt22a
LenovoIdeacentre 3 07iab7 Firmware< m49kt1da
LenovoIdeacentre 3-07imb05 Firmware< m2vkt1da
LenovoIdeacentre 5 14iab7 Firmware< m42kt40a
LenovoIdeacentre 5-14acn6 Firmware< o5ekt21a
LenovoIdeacentre 5-14imb05 Firmware< o4hkt38a
LenovoIdeacentre 5-14iob6 Firmware< m3gkt33a
LenovoIdeacentre Creator 5-14iob6 Firmware<= m3gkt33a
LenovoIdeacentre G5-14imb05 Firmware< o4hkt38a
LenovoIdeacentre Gaming 5 17acn7 Firmware< o5ekt21a
LenovoIdeacentre Gaming 5 17iab7 Firmware< m42kt40a
LenovoIdeacentre Gaming 5-14acn6 Firmware< o5ekt21a
LenovoIdeacentre Gaming 5-14iob6 Firmware< m3gkt33a
LenovoLegion C530-19icb Firmware< o4bkt20a
LenovoLegion T5-26iob6 Firmware< o54kt1da
LenovoLegion T5-28icb05 Firmware< o4bkt20a
LenovoLegion T530-28apr Firmware< o4gkt16a
LenovoLegion T530-28icb Firmware< o4bkt20a
LenovoLegion T7-34imz5 Firmware< o4lkt1ea
LenovoThinkcentre M60e Tiny Firmware< m3skt21a
LenovoThinkcentre M625q Firmware< m1wkt45a
LenovoThinkcentre M630e Firmware< m28kt37a
LenovoThinkcentre M70a Firmware< m2skt25a
LenovoThinkcentre M70a Gen 2 Firmware< m3nkt20a
LenovoThinkcentre M70c Firmware< m2vkt1da
LenovoThinkcentre M70q Firmware< m2wkt57a
LenovoThinkcentre M70q Gen 2 Firmware< m2wkt57a
LenovoThinkcentre M70q Gen 3 Firmware< m43kt16a
LenovoThinkcentre M70s Gen 3 Firmware< m41kt2da
LenovoThinkcentre M70t Gen 3 Firmware< m41kt2da
LenovoThinkcentre M710e Firmware< m1zkt38a
LenovoThinkcentre M710q Firmware< m1akt56a
LenovoThinkcentre M710s Firmware< m16kt68a
LenovoThinkcentre M710t Firmware< m16kt68a
LenovoThinkcentre M715q Firmware< m11kt54a
LenovoThinkcentre M715t Firmware< m2ckt4da
LenovoThinkcentre M720e Firmware< m30kt26a
LenovoThinkcentre M720q Firmware< m1ukt67a
LenovoThinkcentre M720s Firmware< m1ukt67a
LenovoThinkcentre M720t Firmware< m1ukt67a
LenovoThinkcentre M725s Firmware< m25kt61a
LenovoThinkcentre M75n Firmware< m33kt25a
LenovoThinkcentre M75q Gen 2 Firmware< m47kt24a
LenovoThinkcentre M75q-1 Firmware< m2fkt2da
LenovoThinkcentre M75s Gen 2 Firmware< m46kt2da
LenovoThinkcentre M75s-1 Firmware< m2ckt4da
LenovoThinkcentre M75t Gen 2 Firmware< m46kt2da
LenovoThinkcentre M80q Firmware< m2wkt57a
LenovoThinkcentre M810z Firmware< m1ckt49a

Showing 50 of 138 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-40135?
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
How severe is CVE-2022-40135?
CVE-2022-40135 has a CVSS score of 4.4/10 (MEDIUM severity). The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2022-40135?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-40135?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST