CVE-2022-3431Incorrect Default Permissions in Lenovo D330-10igl Firmware

Severity
7.8HIGHNVD
CNA6.7CISA8.8
EPSS
0.0%
top 89.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 9

Description

A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages26 packages

🔴Vulnerability Details

2
GHSA
GHSA-jgmr-c4c9-rqmx: A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated m2023-10-09
CVEList
CVE-2022-3431: A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated m2023-10-09

📋Vendor Advisories

1
CISA
Oracle VirtualBox Insufficient Input Validation Vulnerability2022-03-03
CVE-2022-3431 — Incorrect Default Permissions in Lenovo | cvebase