Vulnerability Description
An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Ideacentre C5-14Imb05 Firmware | < o4hkt3aa |
| Lenovo | Ideacentre C5-14Imb05 | - |
| Lenovo | Ideacentre 3 07Ach7 Firmware | < m4mkt12a |
| Lenovo | Ideacentre 3 07Ach7 | - |
| Lenovo | Ideacentre 3 07Iab7 Firmware | < m49kt21a |
| Lenovo | Ideacentre 3 07Iab7 | - |
| Lenovo | Ideacentre 3-07Ada05 Firmware | < o4fkt35a |
| Lenovo | Ideacentre 3-07Ada05 | - |
| Lenovo | Ideacentre 3-07Imb05 Firmware | < m2vkt1ea |
| Lenovo | Ideacentre 3-07Imb05 | - |
| Lenovo | Ideacentre 5 14Iab7 Firmware | < m42kt42a |
| Lenovo | Ideacentre 5 14Iab7 | - |
| Lenovo | Ideacentre 5-14Acn6 Firmware | < o5ekt24a |
| Lenovo | Ideacentre 5-14Acn6 | - |
| Lenovo | Ideacentre 5-14Are05 Firmware | < o4zkt2aa |
| Lenovo | Ideacentre 5-14Are05 | - |
| Lenovo | Ideacentre 5-14Imb05 Firmware | < o4hkt3aa |
| Lenovo | Ideacentre 5-14Imb05 | - |
| Lenovo | Ideacentre 5-14Iob6 Firmware | < m3gkt3aa |
| Lenovo | Ideacentre 5-14Iob6 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-124495Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-124495Vendor Advisory
FAQ
What is CVE-2022-48181?
CVE-2022-48181 is a vulnerability with a CVSS score of 6.7 (MEDIUM). An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.
How severe is CVE-2022-48181?
CVE-2022-48181 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-48181?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Ideacentre C5-14Imb05 Firmware, Lenovo Ideacentre C5-14Imb05, Lenovo Ideacentre 3 07Ach7 Firmware, Lenovo Ideacentre 3 07Ach7, Lenovo Ideacentre 3 07Iab7 Firmware.