CVE-2022-3430 is a medium-severity vulnerability affecting certain Lenovo Notebook devices, where a flaw in the WMI Setup driver allows an attacker with elevated privileges to modify Secure Boot settings by manipulating an NVRAM variable. This local attack (AV:L) requires high privileges (PR:H) and has a high impact on confidentiality, integrity, and availability (C:H/I:H/A:H), as indicated by its CVSS score of 6.7. While there is no known active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< g0cn11wwCPE matchmatch criteria | cpe:2.3:o:lenovo:d330-10igl_firmware:*:*:*:*:*:*:*:* | ||
< j4cn33wwCPE matchmatch criteria | cpe:2.3:o:lenovo:ideapad_5_pro_16iah7_firmware:*:*:*:*:*:*:*:* | ||
< j5cn27wwCPE matchmatch criteria | cpe:2.3:o:lenovo:ideapad_5_pro_16arh7_firmware:*:*:*:*:*:*:*:* | ||
< eqcn37wwCPE matchmatch criteria | cpe:2.3:o:lenovo:ideapad_duet_3_10igl5_firmware:*:*:*:*:*:*:*:* | ||
< klcn15wwCPE matchmatch criteria | cpe:2.3:o:lenovo:slim_7_16arh7_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.