PT-2023-2193 · Lenovo · Thinkpad X1 Fold Gen 1

Published

2023-03-14

·

Updated

2024-09-06

·

CVE-2022-4573

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ThinkPad X1 Fold Gen 1 (affected versions not specified)
Description A vulnerability exists due to insufficient input validation in the SMI handler of the ThinkPad X1 Fold Gen 1's BIOS firmware. This could allow an attacker with local access and elevated privileges to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-01938
CVE-2022-4573

Affected Products

Thinkpad X1 Fold Gen 1