CVE-2023-45075
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
08/11/2023
Last modified:
16/11/2023
Description
A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:lenovo:ideacentre_c5-14imb05_firmware:*:*:*:*:*:*:*:* | o4hkt3ca (excluding) | |
| cpe:2.3:h:lenovo:ideacentre_c5-14imb05:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:ideacentre_3-07ada05_firmware:*:*:*:*:*:*:*:* | o4fkt39a (excluding) | |
| cpe:2.3:h:lenovo:ideacentre_3-07ada05:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:ideacentre_3-07imb05_firmware:*:*:*:*:*:*:*:* | m2vkt21a (excluding) | |
| cpe:2.3:h:lenovo:ideacentre_3-07imb05:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:ideacentre_g5-14imb05_firmware:*:*:*:*:*:*:*:* | o4hkt3ca (excluding) | |
| cpe:2.3:h:lenovo:ideacentre_g5-14imb05:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:ideacentre_5-14iob6_firmware:*:*:*:*:*:*:*:* | m3gkt3da (excluding) | |
| cpe:2.3:h:lenovo:ideacentre_5-14iob6:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:ideacentre_creator_5-14iob6_firmware:*:*:*:*:*:*:*:* | m3gkt3da (excluding) | |
| cpe:2.3:h:lenovo:ideacentre_creator_5-14iob6:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:ideacentre_g5-14amr05_firmware:*:*:*:*:*:*:*:* | o4zkt2ba (excluding) | |
| cpe:2.3:h:lenovo:ideacentre_g5-14amr05:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:ideacentre_g5-14imb05_firmware:*:*:*:*:*:*:*:* | o4hkt3ca (excluding) |
To consult the complete list of CPE names with products and versions, see this page



