CVE-2022-4575
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.
Published:Oct 30, 2023
Last Modified:Nov 21, 2024
EPS:Oct 30, 2023
EPSS Score:0.00005
CVSS Score:6.7
Affected Products
Vendor
Product
Action
Vendor
Lenovo
Product
Thinkpad 25
Lenovo
Thinkpad 25
Vendor
Lenovo
Product
Thinkpad 25 Firmware
Lenovo
Thinkpad 25 Firmware
Vendor
Lenovo
Product
Thinkpad L560
Lenovo
Thinkpad L560
Vendor
Lenovo
Product
Thinkpad L560 Firmware
Lenovo
Thinkpad L560 Firmware
Vendor
Lenovo
Product
Thinkpad P50
Lenovo
Thinkpad P50
Vendor
Lenovo
Product
Thinkpad P50 Firmware
Lenovo
Thinkpad P50 Firmware
Vendor
Lenovo
Product
Thinkpad P50s
Lenovo
Thinkpad P50s
Vendor
Lenovo
Product
Thinkpad P50s Firmware
Lenovo
Thinkpad P50s Firmware
Vendor
Lenovo
Product
Thinkpad P70
Lenovo
Thinkpad P70
Vendor
Lenovo
Product
Thinkpad P70 Firmware
Lenovo
Thinkpad P70 Firmware
Vendor
Lenovo
Product
Thinkpad T470
Lenovo
Thinkpad T470
Vendor
Lenovo
Product
Thinkpad T470 Firmware
Lenovo
Thinkpad T470 Firmware
Vendor
Lenovo
Product
Thinkpad T470s
Lenovo
Thinkpad T470s
Vendor
Lenovo
Product
Thinkpad T470s Firmware
Lenovo
Thinkpad T470s Firmware
Vendor
Lenovo
Product
Thinkpad T560
Lenovo
Thinkpad T560
Vendor
Lenovo
Product
Thinkpad T560 Firmware
Lenovo
Thinkpad T560 Firmware
Vendor
Lenovo
Product
Thinkpad X1 Carbon 4th Gen
Lenovo
Thinkpad X1 Carbon 4th Gen
Vendor
Lenovo
Product
Thinkpad X1 Carbon 4th Gen Firmware
Lenovo
Thinkpad X1 Carbon 4th Gen Firmware
Vendor
Lenovo
Product
Thinkpad X1 Yoga 1st Gen
Lenovo
Thinkpad X1 Yoga 1st Gen
Vendor
Lenovo
Product
Thinkpad X1 Yoga 1st Gen Firmware
Lenovo
Thinkpad X1 Yoga 1st Gen Firmware
Vendor
Lenovo
Product
Thinkpad X260
Lenovo
Thinkpad X260
Vendor
Lenovo
Product
Thinkpad X260 Firmware
Lenovo
Thinkpad X260 Firmware
Vendor
Lenovo
Product
Thinkpad X270
Lenovo
Thinkpad X270
Vendor
Lenovo
Product
Thinkpad X270 Firmware
Lenovo
Thinkpad X270 Firmware
Vendor
Lenovo
Product
Thinkpad Yoga 260
Lenovo
Thinkpad Yoga 260
Vendor
Lenovo
Product
Thinkpad Yoga 260 Firmware
Lenovo
Thinkpad Yoga 260 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
