PT-2022-3667 · Lenovo · Lenovo Thinkedge+3
Published
2022-07-13
·
Updated
2023-02-08
·
CVE-2022-34888
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Lenovo ThinkSystem versions (affected versions not specified)
Lenovo ThinkStation versions (affected versions not specified)
Lenovo ThinkEdge versions (affected versions not specified)
Lenovo ThinkAgile versions (affected versions not specified)
Description
The issue is related to a buffer overflow in the memory of the Remote Presence subsystem of the Lenovo software. This can potentially allow a remote attacker to elevate their privileges. Additionally, the Remote Mount feature can be abused by authenticated users to access internal services that are not normally accessible, although internal service access controls remain in effect.
Recommendations
For Lenovo ThinkSystem, update to a version that fixes the buffer overflow issue in the Remote Presence subsystem.
For Lenovo ThinkStation, restrict access to the Remote Mount feature to prevent abuse by authenticated users.
For Lenovo ThinkEdge, consider disabling the Remote Mount feature until a patch is available to prevent potential exploitation.
For Lenovo ThinkAgile, apply internal service access controls to minimize the risk of unauthorized access to internal services.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lenovo Thinkagile
Lenovo Thinkedge
Lenovo Thinkstation
Lenovo Thinksystem