← back
CVE-2022-48182mediumCWE-1263

CVE-2022-48182

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.1epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
In short

The BIOS tamper detection in certain ThinkPad laptops can fail to trigger under specific conditions, potentially allowing unauthorized people to access or modify the system's core software without being detected.

Technical detail

A bypass in the BIOS tamper detection mechanism (CWE-1263: Improper Validation of Specified Quantity in Input) on ThinkPad T14s Gen 3 and X13 Gen3 allows an attacker with physical access to circumvent security alerts when tampering with firmware. Detection failure occurs only under specific circumstances, reducing the effectiveness of this critical security control.

Summary generated and translated by AI from the official description.
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H