CVE-2022-3746 MEDIUM

CVE-2022-3746

Vendor Lenovo
Product Notebook
Weakness CWE-284
Published August 23, 2023
Last update August 3, 2024

CVSS base score

6.7/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.

Key dates

02Disclosure timeline

August 23, 2023 CVE published
August 3, 2024 Record updated