ThinkPad X13s BIOS Vulnerabilities

ThinkPad X13s BIOS Vulnerabilities

ThinkPad X13s BIOS Vulnerabilities

Lenovo Security Advisory: LEN-103709

Potential Impact: Memory corruption, information disclosure

Severity: High

Scope of Impact: Lenovo-specific

CVE Identifier: CVE-2022-40516, CVE-2022-40517, CVE-2022-40518, CVE-2022-40519, CVE-2022-40520, CVE-2022-4432, CVE-2022-4433, CVE-2022-4434, CVE-2022-4435

 

Summary Description:

The following vulnerabilities were reported in the ThinkPad X13s BIOS.

CVE-2022-40516, CVE-2022-40517, CVE-2022-40520: Qualcomm reported several stack-based buffer overflow vulnerabilities in Qualcomm BIOS that could allow a local attacker with elevated privileges to cause memory corruption.

CVE-2022-40518, CVE-2022-40519: Qualcomm reported several buffer over-read vulnerabilities in Qualcomm BIOS that could allow a local attacker with elevated privileges to cause information disclosure.

CVE-2022-4432, CVE-2022-4433, CVE-2022-4434, CVE-2022-4435: Several buffer over-read vulnerabilities were reported in ThinkPad X13s BIOS that could allow a local attacker with elevated privileges to cause information disclosure.

 

 

Mitigation Strategy for Customers (what you should do to protect yourself):

Update ThinkPad X13s BIOS to version 1.47 (N3HET75W) or newer

 

Acknowledgement:

Lenovo thanks BINARLY efiXplorer team for reporting these issues.

 

References:

Qualcomm Advisory: https://docs.qualcomm.com/product/publicresources/securitybulletin

ThinkPad X13s BIOS Download: https://pcsupport.lenovo.com/us/en/products/laptops-and-netbooks/thinkpad-x-series-laptops/thinkpad-x13s-type-21bx-21by/downloads/ds556845-bios-update-utility-bootable-cd-for-windows-11-thinkpad-x13s-gen-1-type-21bx-21by?category=BIOS%2FUEFI

 

Revision History:

Revision Date Description
1 2023-01-03 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an “as is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.


Alias Id:LEN-103709
Document ID:PS500537
Original Publish Date:01/03/2023
Last Modified Date:01/03/2023