MEDIUM · 4.4

CVE-2023-43568

A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

Vulnerability Description

A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

CVSS Score

4.4

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LenovoIdeacentre C5-14Imb05 Firmware< o4hkt3ca
LenovoIdeacentre C5-14Imb05-
LenovoIdeacentre 3-07Ada05 Firmware< o4fkt39a
LenovoIdeacentre 3-07Ada05-
LenovoIdeacentre 3-07Imb05 Firmware< m2vkt21a
LenovoIdeacentre 3-07Imb05-
LenovoIdeacentre 5 14Iab7 Firmware< m42kt46a
LenovoIdeacentre 5 14Iab7-
LenovoIdeacentre 5 14Irb8 Firmware< m4ukt36a
LenovoIdeacentre 5 14Irb8-
LenovoIdeacentre 5-14Acn6 Firmware-
LenovoIdeacentre 5-14Acn6-
LenovoIdeacentre T540-15Ama G Firmware-
LenovoIdeacentre T540-15Ama G-
LenovoThinkcentre Neo 70T Gen 3 Firmware< m40kt45a
LenovoThinkcentre Neo 70T Gen 3-
LenovoThinkcentre Neo 50T Gen 3 Firmware< m42kt46a
LenovoThinkcentre Neo 50T Gen 3-
LenovoThinkcentre Neo 50A 24 Gen 4 Firmware< o5xkt18a
LenovoThinkcentre Neo 50A 24 Gen 4-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-43568?

CVE-2023-43568 is a vulnerability with a CVSS score of 4.4 (MEDIUM). A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

How severe is CVE-2023-43568?

CVE-2023-43568 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-43568?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Ideacentre C5-14Imb05 Firmware, Lenovo Ideacentre C5-14Imb05, Lenovo Ideacentre 3-07Ada05 Firmware, Lenovo Ideacentre 3-07Ada05, Lenovo Ideacentre 3-07Imb05 Firmware.