CVE-2023-45079Medium
CVE
CVE
National Vulnerability Database
NVD is the U.S. government repository of standards-based vulnerability management data, built on top of the MITRE CVE list. Every record includes CPE applicability statements, CVSS v2 and v3.x base scores, CWE mappings and cross-references to advisories.
Region
US
Updates
15 min
License
Public Domain
Comprehensive catalog of publicly disclosed vulnerabilities with CPE matches, CVSS scoring and reference URLs. De-facto standard for cross-vendor correlation.
https://nvd.nist.gov →Share link
Anyone with the link can open this vulnerability.
A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write t…
CVSS
6.7
Medium
EPSS
0.00
p11
Published
2023-01-01
Updated
2023-01-01
Description
A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
Tags · CWE
CWE-125
CWE-125BaseDraft
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://cwe.mitre.org/data/definitions/125.html →Open in CWE collection →CAPEC-540
CAPEC-540StandardDraft
Overread Buffers
An adversary attacks a target by providing input that causes an application to read beyond the boundary of a defined buffer. This typically occurs when a value influencing where to start or stop reading is set to reflect positions outside of the valid memory location of the buffer. This type of attack may result in exposure of sensitive information, a system crash, or arbitrary code execution.
https://capec.mitre.org/data/definitions/540.html →Open in CAPEC collection →Affected products
Ideacentre_3-07ada05_firmwareIdeacentre_3-07imb05_firmwareIdeacentre_5-14iob6_firmwareIdeacentre_c5-14imb05_firmwareIdeacentre_creator_5-14iob6_firmwareIdeacentre_g5-14amr05_firmwareIdeacentre_g5-14imb05_firmwareIdeacentre_g5-14imb05_firmwareIdeacentre_gaming_5-14iob6_firmwareIdeacentre_mini_5-01imh05_firmwareIdeacentre_mini_5_01iaq7_firmwareLegion_t7-34imz5_firmwareThinkcentre_m625q_firmwareThinkcentre_m630e_firmwareThinkcentre_m70a_firmwareThinkcentre_m70c_firmwareThinkcentre_m70c_firmwareThinkcentre_m70q_firmwareThinkcentre_m70s_firmwareThinkcentre_m70t_firmware
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: H
High (H)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.002 · p11
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
| Product | Vendor | Status |
|---|---|---|
| ideacentre_3-07ada05_firmware | * | Tracked |
| ideacentre_3-07imb05_firmware | * | Tracked |
| ideacentre_5-14iob6_firmware | * | Tracked |
| ideacentre_c5-14imb05_firmware | * | Tracked |
| ideacentre_creator_5-14iob6_firmware | * | Tracked |
| ideacentre_g5-14amr05_firmware | * | Tracked |
| ideacentre_g5-14imb05_firmware | * | Tracked |
| ideacentre_g5-14imb05_firmware | * | Tracked |
| ideacentre_gaming_5-14iob6_firmware | * | Tracked |
| ideacentre_mini_5-01imh05_firmware | * | Tracked |
| ideacentre_mini_5_01iaq7_firmware | * | Tracked |
| legion_t7-34imz5_firmware | * | Tracked |
| thinkcentre_m625q_firmware | * | Tracked |
| thinkcentre_m630e_firmware | * | Tracked |
| thinkcentre_m70a_firmware | * | Tracked |
| thinkcentre_m70c_firmware | * | Tracked |
| thinkcentre_m70c_firmware | * | Tracked |
| thinkcentre_m70q_firmware | * | Tracked |
| thinkcentre_m70s_firmware | * | Tracked |
| thinkcentre_m70t_firmware | * | Tracked |
Showing first 20 of 64
Source databases
CVE
CVE
National Vulnerability Database
NVD is the U.S. government repository of standards-based vulnerability management data, built on top of the MITRE CVE list. Every record includes CPE applicability statements, CVSS v2 and v3.x base scores, CWE mappings and cross-references to advisories.
Region
US
Updates
15 min
License
Public Domain
Comprehensive catalog of publicly disclosed vulnerabilities with CPE matches, CVSS scoring and reference URLs. De-facto standard for cross-vendor correlation.
https://nvd.nist.gov →