MEDIUM · 6.7

CVE-2022-4575

A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the a...

Vulnerability Description

A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoThinkpad 25 Firmware< 1.73
LenovoThinkpad 25-
LenovoThinkpad L560 Firmware< 1.62
LenovoThinkpad L560-
LenovoThinkpad P50 Firmware< 1.71
LenovoThinkpad P50-
LenovoThinkpad P50S Firmware< 1.45
LenovoThinkpad P50S-
LenovoThinkpad P70 Firmware< 2.45
LenovoThinkpad P70-
LenovoThinkpad T470 Firmware< 1.73
LenovoThinkpad T470-
LenovoThinkpad T470S Firmware< 1.49
LenovoThinkpad T470S-
LenovoThinkpad T560 Firmware< 1.45
LenovoThinkpad T560-
LenovoThinkpad X1 Carbon 4Th Gen Firmware< 1.56
LenovoThinkpad X1 Carbon 4Th Gen-
LenovoThinkpad X1 Yoga 1St Gen Firmware< 1.56
LenovoThinkpad X1 Yoga 1St Gen-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-4575?

CVE-2022-4575 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the a...

How severe is CVE-2022-4575?

CVE-2022-4575 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-4575?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkpad 25 Firmware, Lenovo Thinkpad 25, Lenovo Thinkpad L560 Firmware, Lenovo Thinkpad L560, Lenovo Thinkpad P50 Firmware.