CVE-2018-9062

In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
lenovoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
VendorProductVersion
lenovoe42-80_firmware
𝑥
< 2wcn40ww
lenovoe42-80_isk_firmware
𝑥
< 0zcn48ww
lenovoe52-80_firmware
𝑥
< 2wcn40ww
lenovoe52-80_isk_firmware
𝑥
< 0zcn48ww
lenovomiix_720-12ikb_firmware
𝑥
< 3scn68ww
lenovov310-14ikb_firmware
𝑥
< 2wcn40ww
lenovov310-14isk_firmware
𝑥
< 0zcn48ww
lenovov310-15ikb_firmware
𝑥
< 2wcn40ww
lenovov310-15isk_firmware
𝑥
< 0zcn48ww
lenovov510-14ikb_firmware
𝑥
< 2wcn40ww
lenovov510-15ikb_firmware
𝑥
< 2wcn40ww
lenovothinkpad_l380_firmware
𝑥
< r0ret28w
lenovothinkpad_e480_firmware
𝑥
< r0pet47w
lenovothinkpad_e580_firmware
𝑥
< r0pet47w
lenovothinkpad_l480_firmware
𝑥
< r0qet47w
lenovothinkpad_l580_firmware
𝑥
< r0qet47w
lenovothinkpad_t470p_firmware
𝑥
< r0fet44w
lenovothinkpad_x380_yoga_firmware
𝑥
< r0set29w
lenovothinkpad_yoga_11e_firmware
𝑥
< r0vet23w
lenovothinkpad_yoga_370_firmware
𝑥
< r0het48w
lenovothinkpad_s1_firmware
𝑥
< r0het48w
lenovothinkpad_x270_firmware
𝑥
< r0iet53w
𝑥
= Vulnerable software versions