A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.

Project Subscriptions

Vendors Products
Thinkpad L13 Gen 2 Subscribe
Thinkpad L13 Gen 2 Firmware Subscribe
Thinkpad L13 Gen 3 Subscribe
Thinkpad L13 Gen 3 Firmware Subscribe
Thinkpad L13 Gen 4 Subscribe
Thinkpad L13 Gen 4 Firmware Subscribe
Thinkpad L13 Yoga Gen 2 Subscribe
Thinkpad L13 Yoga Gen 2 Firmware Subscribe
Thinkpad L13 Yoga Gen 3 Subscribe
Thinkpad L13 Yoga Gen 3 Firmware Subscribe
Thinkpad L13 Yoga Gen 4 Subscribe
Thinkpad L13 Yoga Gen 4 Firmware Subscribe
Thinkpad L14 Gen 3 Subscribe
Thinkpad L14 Gen 3 Firmware Subscribe
Thinkpad L14 Gen 4 Subscribe
Thinkpad L14 Gen 4 Firmware Subscribe
Thinkpad L15 Gen 3 Subscribe
Thinkpad L15 Gen 3 Firmware Subscribe
Thinkpad L15 Gen 4 Subscribe
Thinkpad L15 Gen 4 Firmware Subscribe
Thinkpad P14s Gen 3 Subscribe
Thinkpad P14s Gen 3 Firmware Subscribe
Thinkpad P16s Gen 1 Subscribe
Thinkpad P16s Gen 1 Firmware Subscribe
Thinkpad S2 Gen 8 Subscribe
Thinkpad S2 Gen 8 Firmware Subscribe
Thinkpad S2 Yoga Gen 6 Subscribe
Thinkpad S2 Yoga Gen 6 Firmware Subscribe
Thinkpad S2 Yoga Gen 7 Subscribe
Thinkpad S2 Yoga Gen 7 Firmware Subscribe
Thinkpad S2 Yoga Gen 8 Subscribe
Thinkpad S2 Yoga Gen 8 Firmware Subscribe
Thinkpad T14 Gen 3 Subscribe
Thinkpad T14 Gen 3 Firmware Subscribe
Thinkpad T14s Gen 3 Subscribe
Thinkpad T14s Gen 3 Firmware Subscribe
Thinkpad T16 Gen 1 Subscribe
Thinkpad T16 Gen 1 Firmware Subscribe
Thinkpad X13 Gen 3 Subscribe
Thinkpad X13 Gen 3 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-57418 A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-141775


Workaround

No workaround given by the vendor.

History

Mon, 16 Sep 2024 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Mon, 16 Sep 2024 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1419

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-16T14:52:18.065Z

Reserved: 2023-09-19T20:53:37.522Z

Link: CVE-2023-5078

cve-icon Vulnrichment

Updated: 2024-08-02T07:44:53.770Z

cve-icon NVD

Status : Modified

Published: 2023-11-08T22:15:11.957

Modified: 2024-11-21T08:41:01.363

Link: CVE-2023-5078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses