First published: Wed Nov 08 2023(Updated: )
A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
lenovo ThinkPad X13 Gen 3 firmware | ||
lenovo ThinkPad X13 Gen 3 firmware | ||
All of | ||
Lenovo ThinkPad S2 Yoga Gen 7 Firmware | <1.19 | |
lenovo ThinkPad s2 yoga gen 7 | ||
All of | ||
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | ||
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | ||
All of | ||
lenovo ThinkPad s2 gen 8 firmware | ||
Lenovo ThinkPad S2 Gen 8 | ||
All of | ||
Lenovo ThinkPad P14s Gen 3 Firmware | ||
Lenovo ThinkPad P14s Gen 3 Firmware | ||
All of | ||
Lenovo ThinkPad P16s Gen 1 Firmware | ||
Lenovo ThinkPad P16s Gen 1 Firmware | ||
All of | ||
Lenovo ThinkPad T14 Gen 3 Firmware | ||
Lenovo ThinkPad T14 Gen 3 Firmware | ||
All of | ||
Lenovo ThinkPad T14s Gen 3 firmware | ||
Lenovo ThinkPad T14s Gen 3 firmware | ||
All of | ||
Lenovo ThinkPad T16 Gen 1 Firmware | ||
Lenovo ThinkPad T16 Gen 1 Firmware | ||
All of | ||
lenovo ThinkPad l14 gen 3 firmware | <1.23 | |
Lenovo ThinkPad L14 Gen 3 | ||
All of | ||
lenovo ThinkPad L14 Gen 4 firmware | <1.1 | |
lenovo ThinkPad L14 Gen 4 firmware | ||
All of | ||
Lenovo ThinkPad L15 Gen 3 Firmware | <1.23 | |
Lenovo ThinkPad L15 Gen 3 Firmware | ||
All of | ||
Lenovo ThinkPad L15 Gen 4 | <1.1 | |
Lenovo ThinkPad L15 Gen 4 Firmware | ||
All of | ||
Lenovo ThinkPad L13 Yoga Gen 4 | ||
Lenovo ThinkPad L13 Yoga Gen 4 Firmware | ||
All of | ||
Lenovo ThinkPad L13 Yoga Gen 3 | <1.19 | |
Lenovo ThinkPad L13 Yoga Gen 3 Firmware | ||
All of | ||
Lenovo ThinkPad L13 Yoga Gen 2 | ||
Lenovo ThinkPad L13 Yoga Gen 2 Firmware | ||
All of | ||
Lenovo ThinkPad L13 Gen 4 Firmware | ||
Lenovo ThinkPad L13 Gen 4 Firmware | ||
All of | ||
Lenovo ThinkPad L13 Yoga Gen 3 Firmware | <1.19 | |
Lenovo ThinkPad L13 Yoga Gen 3 | ||
All of | ||
Lenovo ThinkPad L13 Gen 2 | ||
Lenovo ThinkPad L13 Gen 2 Firmware | ||
All of | ||
Lenovo ThinkPad S2 Yoga Gen 8 Firmware | ||
Lenovo ThinkPad S2 Gen 8 |
Update system firmware to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-141775
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-5078.
The severity of CVE-2023-5078 is medium.
Lenovo Thinkpad X13 Gen 3 is affected by CVE-2023-5078.
A physical or local attacker with elevated privileges can exploit CVE-2023-5078 to tamper with BIOS firmware.
You can find more information about CVE-2023-5078 at the following link: [CVE-2023-5078](https://support.lenovo.com/us/en/product_security/LEN-141775)