cbcvebase.

Lenovo Ideacentre Gaming 5-14Iob6 Firmware vulnerabilities

26 known vulnerabilities affecting lenovo/ideacentre_gaming_5-14iob6_firmware.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM25

Vulnerabilities

Page 2 of 2
CVE-2022-40134P4MEDIUMCVSS 4.4vm3gkt33a2023-01-30
CVE-2022-40134 [MEDIUM] CWE-125 CVE-2022-40134: An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
nvd
CVE-2022-40135P4MEDIUMCVSS 4.4fixed in m3gkt33a2023-01-30
CVE-2022-40135 [MEDIUM] CWE-125 CVE-2022-40135: An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
nvd
CVE-2022-40136P4MEDIUMCVSS 4.4fixed in m3gkt33a2023-01-30
CVE-2022-40136 [MEDIUM] CWE-125 CVE-2022-40136: An information leak vulnerability in SMI Handler used to configure platform settings over WMI in som An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
nvd
CVE-2023-43568P4MEDIUMCVSS 4.4fixed in m3gkt3da2023-11-08
CVE-2023-43568 [MEDIUM] CWE-126 CVE-2023-43568: A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
nvd
CVE-2023-43574P4MEDIUMCVSS 4.4fixed in m3gkt3da2023-11-08
CVE-2023-43574 [MEDIUM] CWE-126 CVE-2023-43574: A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
nvd
CVE-2023-43572P4MEDIUMCVSS 4.4fixed in m3gkt3da2023-11-08
CVE-2023-43572 [MEDIUM] CWE-126 CVE-2023-43572: A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products th A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
nvd