MEDIUM · 6.7

CVE-2023-45076

A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

Vulnerability Description

A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoIdeacentre C5-14Imb05 Firmware< o4hkt3ca
LenovoIdeacentre C5-14Imb05-
LenovoIdeacentre 3-07Ada05 Firmware< o4fkt39a
LenovoIdeacentre 3-07Ada05-
LenovoIdeacentre 3-07Imb05 Firmware< m2vkt21a
LenovoIdeacentre 3-07Imb05-
LenovoIdeacentre G5-14Imb05 Firmware< o4hkt3ca
LenovoIdeacentre G5-14Imb05-
LenovoIdeacentre 5-14Iob6 Firmware< m3gkt3da
LenovoIdeacentre 5-14Iob6-
LenovoIdeacentre Creator 5-14Iob6 Firmware< m3gkt3da
LenovoIdeacentre Creator 5-14Iob6-
LenovoIdeacentre G5-14Amr05 Firmware< o4zkt2ba
LenovoIdeacentre G5-14Amr05-
LenovoIdeacentre Gaming 5-14Iob6 Firmware< m3gkt3da
LenovoIdeacentre Gaming 5-14Iob6-
LenovoIdeacentre Mini 5 01Iaq7 Firmware< o53kt10a
LenovoIdeacentre Mini 5 01Iaq7-
LenovoIdeacentre Mini 5-01Imh05 Firmware< o4ekt1ba
LenovoIdeacentre Mini 5-01Imh05-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-45076?

CVE-2023-45076 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

How severe is CVE-2023-45076?

CVE-2023-45076 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-45076?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Ideacentre C5-14Imb05 Firmware, Lenovo Ideacentre C5-14Imb05, Lenovo Ideacentre 3-07Ada05 Firmware, Lenovo Ideacentre 3-07Ada05, Lenovo Ideacentre 3-07Imb05 Firmware.