CVE-2022-48183: Medium severity lenovo thinkpad t14s firmware vulnerability
Published Oct 9, 2023
·Updated
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
Affected Software
8 affected components
Lenovo Thinkpad T14s Gen 3 Firmware<1.30
Lenovo Thinkpad T14s Gen 3
Microsoft Windows
Lenovo Thinkpad X13 Gen 3 Firmware<1.30
Lenovo Thinkpad X13 Gen 3
Lenovo Thinkpad T14s Gen 3 Firmware<1.35
Linux Linux kernel
Lenovo Thinkpad X13 Gen 3 Firmware<1.35
Remediation
Information
Update system firmware to the version 1.30 (R22ET60W)
or newer.
Event History
Oct 9, 2023
CVE Published
via MITRE·08:56 PM
Data Sourced
via MITRE·08:56 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-48183.
2
What is the affected software?
The affected software includes Lenovo ThinkPad T14s Gen 3 Firmware up to version 1.30 and Lenovo ThinkPad X13 Gen 3 Firmware up to version 1.30.
3
What is the severity of CVE-2022-48183?
The severity of CVE-2022-48183 is medium with a CVSS score of 6.1.
4
How does CVE-2022-48183 affect ThinkPad T14s Gen 3 and X13 Gen3?
CVE-2022-48183 could cause the BIOS tamper detection mechanism to not trigger under specific circumstances, allowing unauthorized access.
5
How can I fix CVE-2022-48183?
To fix CVE-2022-48183, users should update their Lenovo ThinkPad T14s Gen 3 and X13 Gen3 firmware to version 1.35 or later.