CVE-2018-9062

CWE-743 documents3 sources
Severity
6.8MEDIUM
EPSS
0.1%
top 64.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateMay 13

Description

In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages40 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4w9p-jrr8-ffxf: In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code2022-05-13
CVEList
BIOS Modules Unprotected by Intel Boot Guard Vulnerable to Physical Attack2018-07-19
CVE-2018-9062 (MEDIUM CVSS 6.8) | In some Lenovo ThinkPad products | cvebase.io