Vulnerability Description
In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | E42-80 Firmware | < 2wcn40ww |
| Lenovo | E42-80 | - |
| Lenovo | E42-80 Isk Firmware | < 0zcn48ww |
| Lenovo | E42-80 Isk | - |
| Lenovo | E52-80 Firmware | < 2wcn40ww |
| Lenovo | E52-80 | - |
| Lenovo | E52-80 Isk Firmware | < 0zcn48ww |
| Lenovo | E52-80 Isk | - |
| Lenovo | Miix 720-12Ikb Firmware | < 3scn68ww |
| Lenovo | Miix 720-12Ikb | - |
| Lenovo | V310-14Ikb Firmware | < 2wcn40ww |
| Lenovo | V310-14Ikb | - |
| Lenovo | V310-14Isk Firmware | < 0zcn48ww |
| Lenovo | V310-14Isk | - |
| Lenovo | V310-15Ikb Firmware | < 2wcn40ww |
| Lenovo | V310-15Ikb | - |
| Lenovo | V310-15Isk Firmware | < 0zcn48ww |
| Lenovo | V310-15Isk | - |
| Lenovo | V510-14Ikb Firmware | < 2wcn40ww |
| Lenovo | V510-14Ikb | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/105387Third Party AdvisoryVDB Entry
- https://support.lenovo.com/us/en/solutions/LEN-20527PatchVendor Advisory
- http://www.securityfocus.com/bid/105387Third Party AdvisoryVDB Entry
- https://support.lenovo.com/us/en/solutions/LEN-20527PatchVendor Advisory
FAQ
What is CVE-2018-9062?
CVE-2018-9062 is a vulnerability with a CVSS score of 6.8 (MEDIUM). In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.
How severe is CVE-2018-9062?
CVE-2018-9062 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9062?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo E42-80 Firmware, Lenovo E42-80, Lenovo E42-80 Isk Firmware, Lenovo E42-80 Isk, Lenovo E52-80 Firmware.