MEDIUM · 4.4

CVE-2022-3743

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumer...

Vulnerability Description

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands.

CVSS Score

4.4

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LenovoIdeapad 1 14Iau7 Firmware< jkcn34ww
LenovoIdeapad 1 14Iau7-
LenovoIdeapad 1 14Igl7 Firmware< kkcn15ww
LenovoIdeapad 1 14Igl7-
LenovoIdeapad 1 15Iau7 Firmware< jkcn34ww
LenovoIdeapad 1 15Iau7-
LenovoIdeapad 1 15Igl7 Firmware< kkcn15ww
LenovoIdeapad 1 15Igl7-
LenovoIdeapad 1-14Ijl7 Firmware< htcn31ww
LenovoIdeapad 1-14Ijl7-
LenovoIdeapad 1-15Ijl7 Firmware< htcn31ww
LenovoIdeapad 1-15Ijl7-
LenovoIdeapad 3 14Iau7 Firmware< jkcn34ww
LenovoIdeapad 3 14Iau7-
LenovoIdeapad 3 15Iau7 Firmware< jkcn34ww
LenovoIdeapad 3 15Iau7-
LenovoIdeapad 3 17Iau7 Firmware< jkcn34ww
LenovoIdeapad 3 17Iau7-
LenovoIdeapad 3-15Igl05 Firmware< dvcn28ww
LenovoIdeapad 3-15Igl05-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-3743?

CVE-2022-3743 is a vulnerability with a CVSS score of 4.4 (MEDIUM). A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumer...

How severe is CVE-2022-3743?

CVE-2022-3743 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-3743?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Ideapad 1 14Iau7 Firmware, Lenovo Ideapad 1 14Iau7, Lenovo Ideapad 1 14Igl7 Firmware, Lenovo Ideapad 1 14Igl7, Lenovo Ideapad 1 15Iau7 Firmware.