CVE-2022-40134 is an information leak vulnerability affecting certain Lenovo models, specifically within the SMI Set BIOS Password SMI Handler. This flaw allows an attacker with local access and elevated privileges to read System Management Mode (SMM) memory. Rated as Medium severity (CVSS 4.4), the vulnerability requires high privileges and local access, but successful exploitation could lead to the compromise of sensitive SMM data. There is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable, with minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
o4hkt38aCPE matchmatch criteria | cpe:2.3:o:lenovo:ideacentre_c5-14imb05_firmware:o4hkt38a:*:*:*:*:*:*:* | ||
m26kt22aCPE matchmatch criteria | cpe:2.3:o:lenovo:thinkcentre_e96z_firmware:m26kt22a:*:*:*:*:*:*:* | ||
m49kt1daCPE matchmatch criteria | cpe:2.3:o:lenovo:ideacentre_3_07iab7_firmware:m49kt1da:*:*:*:*:*:*:* | ||
m2vkt1daCPE matchmatch criteria | cpe:2.3:o:lenovo:ideacentre_3-07imb05_firmware:m2vkt1da:*:*:*:*:*:*:* | ||
m42kt40aCPE matchmatch criteria | cpe:2.3:o:lenovo:ideacentre_5_14iab7_firmware:m42kt40a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.