CVE-2022-3431: High severity lenovo ideapad creator 5-16ach6 vulnerability
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-3431?
CVE-2022-3431 is a potential vulnerability in a driver used during the manufacturing process on some consumer Lenovo Notebook devices.
How does CVE-2022-3431 affect Lenovo devices?
CVE-2022-3431 may allow an attacker with elevated privileges to modify secure boot settings by modifying an NVRAM variable.
Which Lenovo devices are affected by CVE-2022-3431?
Some consumer Lenovo Notebook devices are affected by CVE-2022-3431.
What is the severity of CVE-2022-3431?
CVE-2022-3431 has a severity rating of 7.8, which is considered high.
How can I fix CVE-2022-3431?
To fix CVE-2022-3431, Lenovo has released a firmware update. Please refer to the Lenovo Product Security website for more information and to download the update.