MEDIUM · 6.7

CVE-2022-3744

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded S...

Vulnerability Description

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoIdeapad 1 14Iau7 Firmware< jkcn34ww
LenovoIdeapad 1 14Iau7-
LenovoIdeapad 1 14Igl7 Firmware< kkcn15ww
LenovoIdeapad 1 14Igl7-
LenovoIdeapad 1 15Iau7 Firmware< jkcn34ww
LenovoIdeapad 1 15Iau7-
LenovoIdeapad 1 15Igl7 Firmware< kkcn15ww
LenovoIdeapad 1 15Igl7-
LenovoIdeapad 1-14Ijl7 Firmware< htcn31ww
LenovoIdeapad 1-14Ijl7-
LenovoIdeapad 1-15Ijl7 Firmware< htcn31ww
LenovoIdeapad 1-15Ijl7-
LenovoIdeapad 3 14Iau7 Firmware< jkcn34ww
LenovoIdeapad 3 14Iau7-
LenovoIdeapad 3 15Iau7 Firmware< jkcn34ww
LenovoIdeapad 3 15Iau7-
LenovoIdeapad 3 17Iau7 Firmware< jkcn34ww
LenovoIdeapad 3 17Iau7-
LenovoIdeapad 3-15Igl05 Firmware< dvcn28ww
LenovoIdeapad 3-15Igl05-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-3744?

CVE-2022-3744 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded S...

How severe is CVE-2022-3744?

CVE-2022-3744 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-3744?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Ideapad 1 14Iau7 Firmware, Lenovo Ideapad 1 14Iau7, Lenovo Ideapad 1 14Igl7 Firmware, Lenovo Ideapad 1 14Igl7, Lenovo Ideapad 1 15Iau7 Firmware.