Vulnerability Description
A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Ideacentre C5-14Imb05 Firmware | < o4hkt3ca |
| Lenovo | Ideacentre C5-14Imb05 | - |
| Lenovo | Ideacentre 3-07Ada05 Firmware | < o4fkt39a |
| Lenovo | Ideacentre 3-07Ada05 | - |
| Lenovo | Ideacentre 3-07Imb05 Firmware | < m2vkt21a |
| Lenovo | Ideacentre 3-07Imb05 | - |
| Lenovo | Ideacentre 5 14Iab7 Firmware | < m42kt46a |
| Lenovo | Ideacentre 5 14Iab7 | - |
| Lenovo | Ideacentre 5 14Irb8 Firmware | < m4ukt36a |
| Lenovo | Ideacentre 5 14Irb8 | - |
| Lenovo | Ideacentre 5-14Acn6 Firmware | - |
| Lenovo | Ideacentre 5-14Acn6 | - |
| Lenovo | Ideacentre T540-15Ama G Firmware | - |
| Lenovo | Ideacentre T540-15Ama G | - |
| Lenovo | Thinkcentre Neo 70T Gen 3 Firmware | < m40kt45a |
| Lenovo | Thinkcentre Neo 70T Gen 3 | - |
| Lenovo | Thinkcentre Neo 50T Gen 3 Firmware | < m42kt46a |
| Lenovo | Thinkcentre Neo 50T Gen 3 | - |
| Lenovo | Thinkcentre Neo 50A 24 Gen 4 Firmware | < o5xkt18a |
| Lenovo | Thinkcentre Neo 50A 24 Gen 4 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-141775Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-141775Vendor Advisory
FAQ
What is CVE-2023-43579?
CVE-2023-43579 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
How severe is CVE-2023-43579?
CVE-2023-43579 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-43579?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Ideacentre C5-14Imb05 Firmware, Lenovo Ideacentre C5-14Imb05, Lenovo Ideacentre 3-07Ada05 Firmware, Lenovo Ideacentre 3-07Ada05, Lenovo Ideacentre 3-07Imb05 Firmware.