Description
A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update system firmware to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-141775
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29449 | A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables. |
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-141775 |
|
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-02T11:25:18.856Z
Reserved: 2023-02-06T15:09:03.709Z
Link: CVE-2023-25494
Updated: 2024-08-02T11:25:18.856Z
Status : Deferred
Published: 2024-04-05T21:15:07.813
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-25494
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD