CVE Feed

    Dashboard / CVE / CVE-2022-48188

    CVE-2022-48188

    A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.

    Published:Jun 5, 2023
    Last Modified:Jan 8, 2025
    EPS:Jun 5, 2023
    EPSS Score:0.00032
    CVSS Score:6.7

    Affected Products

    Vendor
    Lenovo
    Product
    Ideacentre 510s-07icb
    Vendor
    Lenovo
    Product
    Ideacentre 510s-07icb Firmware
    Vendor
    Lenovo
    Product
    Ideacentre 510s-07ick
    Vendor
    Lenovo
    Product
    Ideacentre 510s-07ick Firmware
    Vendor
    Lenovo
    Product
    Ideacentre 720-18apr
    Vendor
    Lenovo
    Product
    Ideacentre 720-18apr Firmware
    Vendor
    Lenovo
    Product
    Ideacentre Aio 3-22itl6
    Vendor
    Lenovo
    Product
    Ideacentre Aio 3-22itl6 Firmware
    Vendor
    Lenovo
    Product
    Ideacentre Aio 3-24itl6
    Vendor
    Lenovo
    Product
    Ideacentre Aio 3-24itl6 Firmware
    Vendor
    Lenovo
    Product
    Ideacentre Aio 3-27itl6
    Vendor
    Lenovo
    Product
    Ideacentre Aio 3-27itl6 Firmware
    Vendor
    Lenovo
    Product
    Ideacentre Aio 3 21itl7
    Vendor
    Lenovo
    Product
    Ideacentre Aio 3 21itl7 Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M720e
    Vendor
    Lenovo
    Product
    Thinkcentre M720e Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M720q
    Vendor
    Lenovo
    Product
    Thinkcentre M720q Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M720s
    Vendor
    Lenovo
    Product
    Thinkcentre M720s Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M720t
    Vendor
    Lenovo
    Product
    Thinkcentre M720t Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M725s
    Vendor
    Lenovo
    Product
    Thinkcentre M725s Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M75s Gen 2
    Vendor
    Lenovo
    Product
    Thinkcentre M75s Gen 2 Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M75t Gen 2
    Vendor
    Lenovo
    Product
    Thinkcentre M75t Gen 2 Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M920q
    Vendor
    Lenovo
    Product
    Thinkcentre M920q Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M920s
    Vendor
    Lenovo
    Product
    Thinkcentre M920s Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M920t
    Vendor
    Lenovo
    Product
    Thinkcentre M920t Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M920x
    Vendor
    Lenovo
    Product
    Thinkcentre M920x Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M920z
    Vendor
    Lenovo
    Product
    Thinkcentre M920z Firmware
    Vendor
    Lenovo
    Product
    Thinkstation P330 Tiny
    Vendor
    Lenovo
    Product
    Thinkstation P330 Tiny Firmware
    Vendor
    Lenovo
    Product
    Thinkstation P360 Ultra
    Vendor
    Lenovo
    Product
    Thinkstation P360 Ultra Firmware
    Vendor
    Lenovo
    Product
    Thinkstation P520
    Vendor
    Lenovo
    Product
    Thinkstation P520 Firmware
    Vendor
    Lenovo
    Product
    Thinkstation P520c
    Vendor
    Lenovo
    Product
    Thinkstation P520c Firmware
    Vendor
    Lenovo
    Product
    V30a-22itl
    Vendor
    Lenovo
    Product
    V30a-22itl Firmware
    Vendor
    Lenovo
    Product
    V30a-24itl
    Vendor
    Lenovo
    Product
    V30a-24itl Firmware
    Vendor
    Lenovo
    Product
    V530s-07icb
    Vendor
    Lenovo
    Product
    V530s-07icb Firmware
    Vendor
    Lenovo
    Product
    V530s-07icr
    Vendor
    Lenovo
    Product
    V530s-07icr Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High