MEDIUM · 6.8

CVE-2018-9062

In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

Vulnerability Description

In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoE42-80 Firmware< 2wcn40ww
LenovoE42-80-
LenovoE42-80 Isk Firmware< 0zcn48ww
LenovoE42-80 Isk-
LenovoE52-80 Firmware< 2wcn40ww
LenovoE52-80-
LenovoE52-80 Isk Firmware< 0zcn48ww
LenovoE52-80 Isk-
LenovoMiix 720-12Ikb Firmware< 3scn68ww
LenovoMiix 720-12Ikb-
LenovoV310-14Ikb Firmware< 2wcn40ww
LenovoV310-14Ikb-
LenovoV310-14Isk Firmware< 0zcn48ww
LenovoV310-14Isk-
LenovoV310-15Ikb Firmware< 2wcn40ww
LenovoV310-15Ikb-
LenovoV310-15Isk Firmware< 0zcn48ww
LenovoV310-15Isk-
LenovoV510-14Ikb Firmware< 2wcn40ww
LenovoV510-14Ikb-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-9062?

CVE-2018-9062 is a vulnerability with a CVSS score of 6.8 (MEDIUM). In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

How severe is CVE-2018-9062?

CVE-2018-9062 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-9062?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo E42-80 Firmware, Lenovo E42-80, Lenovo E42-80 Isk Firmware, Lenovo E42-80 Isk, Lenovo E52-80 Firmware.