Products
ThinkPad L390 Yoga
10w Notebook
Source
psirt@lenovo.com
Tags
CVE-2024-7756 details
Published : Sept. 13, 2024, 6:15 p.m.
Last Modified : Sept. 13, 2024, 6:15 p.m.
Last Modified : Sept. 13, 2024, 6:15 p.m.
Description
A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6.8 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-489 | Active Debug Code | The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information. |
CVSS Data
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
6.8
Exploitability Score
0.9
Impact Score
5.9
Base Severity
MEDIUM
Vector String : CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
URL | Source |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-165524 | psirt@lenovo.com |
This website uses the NVD API, but is not approved or certified by it.