Vulnerability Description
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | 100E 2Nd Gen Firmware | < frcn23ww |
| Lenovo | 100E 2Nd Gen | - |
| Lenovo | 100W Gen 3 Firmware | < gacn38ww |
| Lenovo | 100W Gen 3 | - |
| Lenovo | 13W Yoga Firmware | < jacn31ww |
| Lenovo | 13W Yoga | - |
| Lenovo | 14W Gen 2 Firmware | < h0cn21ww |
| Lenovo | 14W Gen 2 | - |
| Lenovo | 300E 2Nd Gen Firmware | < frcn23ww |
| Lenovo | 300E 2Nd Gen | - |
| Lenovo | 300W Gen 3 Firmware | < gacn38ww |
| Lenovo | 300W Gen 3 | - |
| Lenovo | 500W Gen 3 Firmware | < g6cn40ww |
| Lenovo | 500W Gen 3 | - |
| Lenovo | 730S-13Iml Firmware | < brcn20ww |
| Lenovo | 730S-13Iml | - |
| Lenovo | Flex 3-11Ada05 Firmware | < fpcn26ww |
| Lenovo | Flex 3-11Ada05 | - |
| Lenovo | Flex 5-14Alc05 Firmware | < gjcn27ww |
| Lenovo | Flex 5-14Alc05 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-91369Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-91369Vendor Advisory
FAQ
What is CVE-2022-1892?
CVE-2022-1892 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
How severe is CVE-2022-1892?
CVE-2022-1892 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1892?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo 100E 2Nd Gen Firmware, Lenovo 100E 2Nd Gen, Lenovo 100W Gen 3 Firmware, Lenovo 100W Gen 3, Lenovo 13W Yoga Firmware.