cbcvebase.
CVE-2022-3431
published 2023-10-09

CVE-2022-3431: A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
10.7th percentile
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
lenovobios
lenovod330-10igl_firmware< g0cn11wwg0cn11ww
lenovoideapad_5_pro-16ach6_firmware< gscn34wwgscn34ww
lenovoideapad_5_pro-16ihu6_firmware< grcn22wwgrcn22ww
lenovoideapad_5_pro_16arh7_firmware< j4cn33wwj4cn33ww
lenovoideapad_creator_5-16ach6_firmware< gscn34wwgscn34ww
lenovoideapad_duet_3_10igl5_firmware< eqcn37wweqcn37ww
lenovoideapad_slim_7_pro_16ach6_firmware< hucn16wwhucn16ww
lenovos540-15iml_firmware< cncn22wwcncn22ww
lenovoslim_7_16arh7_firmware< klcn15wwklcn15ww
lenovothinkbook_13x_itg_firmware< hlcn30wwhlcn30ww
lenovothinkbook_14_g4_+_ara_firmware< j6cn40wwj6cn40ww
lenovothinkbook_14_g4_+_iap_firmware< hycn40wwhycn40ww
lenovothinkbook_16_g4_+_ara_firmware< j6cn40wwj6cn40ww
lenovothinkbook_16_g4_+_iap_firmware< hycn40wwhycn40ww
lenovothinkbook_16p_nx_arh_firmware< kjcn27wwkjcn27ww
lenovothinkbook_plus_g2_itg_firmware< gycn31wwgycn31ww
lenovothinkbook_plus_g3_iap_firmware< k6cn29wwk6cn29ww
lenovoyoga_duet_7-13iml05_firmware< ercn30wwercn30ww
lenovoyoga_duet_7-13itl6-lte_firmware< gpcn24wwgpcn24ww
lenovoyoga_duet_7-13itl6_firmware< gpcn24wwgpcn24ww
lenovoyoga_slim_7-13acn05_firmware< ghcn28wwghcn28ww
lenovoyoga_slim_7-13itl05_firmware< f7cn39wwf7cn39ww
lenovoyoga_slim_7_carbon_13itl5_firmware< f7cn39wwf7cn39ww
lenovoyoga_slim_7_pro_16ach6_firmware< hucn16wwhucn16ww

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cisa8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.