CVE-2022-3728: Medium severity lenovo thinkpad t14s firmware vulnerability
Published Oct 9, 2023
·Updated
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
Affected Software
4 affected components
Lenovo Thinkpad T14s Gen 3 Firmware<1.30
Lenovo Thinkpad T14s Gen 3
Lenovo Thinkpad X13 Gen 3 Firmware<1.30
Lenovo Thinkpad X13 Gen 3
Remediation
Information
Update system firmware to the version 1.30 (R22ET60W)
or newer.
Event History
Oct 9, 2023
CVE Published
via MITRE·08:48 PM
Data Sourced
via MITRE·08:48 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3728.
2
Which software is affected by this vulnerability?
The Lenovo ThinkPad T14s Gen 3 and X13 Gen3 firmware versions up to 1.30 are affected.
3
What is the severity of CVE-2022-3728?
The severity of CVE-2022-3728 is medium with a CVSS score of 6.1.
4
How can this vulnerability be exploited?
This vulnerability could allow unauthorized access if the BIOS tamper detection mechanism fails to trigger under specific circumstances.
5
How do I fix CVE-2022-3728?
To fix CVE-2022-3728, update the firmware of your Lenovo ThinkPad T14s Gen 3 or X13 Gen3 to version 1.30 or later.