Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-48188


A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 6.7, requiring local system access to exploit with relatively low complexity without requiring user interaction . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 54 products from lenovo, from lenovo, from lenovo and 51 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2023, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2023-06-05T22:15:11.563

Last Modified

2024-11-21T07:32:56.600

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-787
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System lenovo ideacentre_aio_3_21itl7_firmware < o5akt33 Yes
Hardware lenovo ideacentre_aio_3_21itl7 - No
Operating System lenovo ideacentre_aio_3-22itl6_firmware < o5akt33 Yes
Hardware lenovo ideacentre_aio_3-22itl6 - No
Operating System lenovo ideacentre_aio_3-24itl6_firmware < o5akt33 Yes
Hardware lenovo ideacentre_aio_3-24itl6 - No
Operating System lenovo ideacentre_aio_3-27itl6_firmware < o5akt33 Yes
Hardware lenovo ideacentre_aio_3-27itl6 - No
Operating System lenovo thinkcentre_m720e_firmware < m1zkt40a Yes
Hardware lenovo thinkcentre_m720e - No
Operating System lenovo thinkcentre_m720q_firmware < m1ukt70a Yes
Hardware lenovo thinkcentre_m720q - No
Operating System lenovo thinkcentre_m720s_firmware < m1ukt70a Yes
Hardware lenovo thinkcentre_m720s - No
Operating System lenovo thinkcentre_m720t_firmware < m1ukt70a Yes
Hardware lenovo thinkcentre_m720t - No
Operating System lenovo thinkcentre_m725s_firmware < m25kt63a Yes
Hardware lenovo thinkcentre_m725s - No
Operating System lenovo thinkcentre_m75s_gen_2_firmware < m46kt30a Yes
Hardware lenovo thinkcentre_m75s_gen_2 - No
Operating System lenovo thinkcentre_m75s_gen_2_firmware < m3bkt30a Yes
Hardware lenovo thinkcentre_m75s_gen_2 - No
Operating System lenovo thinkcentre_m75t_gen_2_firmware < m46kt30a Yes
Hardware lenovo thinkcentre_m75t_gen_2 - No
Operating System lenovo thinkcentre_m75t_gen_2_firmware < m3akt4ca Yes
Hardware lenovo thinkcentre_m75t_gen_2 - No
Operating System lenovo thinkcentre_m920q_firmware < m1ukt70a Yes
Hardware lenovo thinkcentre_m920q - No
Operating System lenovo thinkcentre_m920s_firmware < m1ukt70a Yes
Hardware lenovo thinkcentre_m920s - No
Operating System lenovo thinkcentre_m920t_firmware < m1ukt70a Yes
Hardware lenovo thinkcentre_m920t - No
Operating System lenovo thinkcentre_m920x_firmware < m1ukt70a Yes
Hardware lenovo thinkcentre_m920x - No
Operating System lenovo thinkcentre_m920z_firmware < m1mkt55a Yes
Hardware lenovo thinkcentre_m920z - No
Operating System lenovo ideacentre_510s-07icb_firmware < m22kt48a Yes
Hardware lenovo ideacentre_510s-07icb - No
Operating System lenovo ideacentre_510s-07icb_firmware < m22kt49a Yes
Hardware lenovo ideacentre_510s-07icb - No
Operating System lenovo ideacentre_510s-07ick_firmware < m30kt28a Yes
Hardware lenovo ideacentre_510s-07ick - No
Operating System lenovo ideacentre_510s-07ick_firmware < m1zkt40a Yes
Hardware lenovo ideacentre_510s-07ick - No
Operating System lenovo ideacentre_720-18apr_firmware < m25kt63a Yes
Hardware lenovo ideacentre_720-18apr - No
Operating System lenovo v30a-22itl_firmware < o5akt33 Yes
Hardware lenovo v30a-22itl - No
Operating System lenovo v30a-24itl_firmware < o5akt33 Yes
Hardware lenovo v30a-24itl - No
Operating System lenovo v530s-07icb_firmware < m22kt49a Yes
Hardware lenovo v530s-07icb - No
Operating System lenovo v530s-07icr_firmware < m1zkt40a Yes
Hardware lenovo v530s-07icr - No
Operating System lenovo thinkstation_p330_tiny_firmware < m1ukt70a Yes
Hardware lenovo thinkstation_p330_tiny - No
Operating System lenovo thinkstation_p360_ultra_firmware < s0fkt27a Yes
Hardware lenovo thinkstation_p360_ultra - No
Operating System lenovo thinkstation_p520_firmware < s03kt58a Yes
Hardware lenovo thinkstation_p520 - No
Operating System lenovo thinkstation_p520c_firmware < s03kt58a Yes
Hardware lenovo thinkstation_p520c - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For lenovo's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.