CVE-2022-4575

Severity
6.7MEDIUM
EPSS
0.0%
top 99.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 30

Description

A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages14 packages

🔴Vulnerability Details

2
CVEList
CVE-2022-4575: A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physi2023-10-30
GHSA
GHSA-4m6r-j49h-94c5: A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physi2023-10-30
CVE-2022-4575 (MEDIUM CVSS 6.7) | A vulnerability due to improper wri | cvebase.io