CVE-2022-48182: Medium severity lenovo thinkpad t14s firmware vulnerability
Published Oct 9, 2023
·Updated
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
Affected Software
8 affected components
Lenovo Thinkpad T14s Gen 3 Firmware<1.30
Lenovo Thinkpad T14s Gen 3
Microsoft Windows
Lenovo Thinkpad X13 Gen 3 Firmware<1.30
Lenovo Thinkpad X13 Gen 3
Lenovo Thinkpad T14s Gen 3 Firmware<1.35
Linux Linux kernel
Lenovo Thinkpad X13 Gen 3 Firmware<1.35
Remediation
Information
Update system firmware to the version 1.30 (R22ET60W)
or newer.
Event History
Oct 9, 2023
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-48182.
2
What is the severity of CVE-2022-48182?
The severity of CVE-2022-48182 is medium with a severity value of 6.1.
3
Which products are affected by CVE-2022-48182?
ThinkPad T14s Gen 3 and X13 Gen3 with firmware versions up to and excluding 1.30 are affected by CVE-2022-48182.
4
How can unauthorized access be achieved through CVE-2022-48182?
Under specific circumstances, the BIOS tamper detection mechanism may fail to trigger, allowing unauthorized access.
5
How can I fix CVE-2022-48182?
Update the firmware of ThinkPad T14s Gen 3 and X13 Gen3 to version 1.30 or newer to fix CVE-2022-48182.