Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2022-1107

6.7 · MEDIUM
Published Apr 22, 2022 lenovo CWE-20 EPSS 0.26% (17th pctl)

Overview

CVE-2022-1107 is a medium-severity vulnerability affecting lenovo thinkpad_11e_firmware. It was published on April 22, 2022 and has a CVSS 3.1 base score of 6.7 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 6.7, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

Remediation

Check the references section for vendor advisories and patches from lenovo. Update thinkpad_11e_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
lenovo thinkpad_11e_firmware >= 0, < n15et78w Affected
lenovo thinkpad_helix_firmware >= 0, < n17eta8w Affected
lenovo thinkpad_l560_firmware >= 0, < n1het85w Affected
lenovo thinkpad_l570_firmware >= 0, < n1xet65w Affected
lenovo thinkpad_p50s_firmware >= 0, < n1ket46w Affected
lenovo thinkpad_p51s_firmware >= 0, < n1vet50w Affected
lenovo thinkpad_p52s_firmware >= 0, < n27et36w Affected
lenovo thinkpad_s540_firmware >= 0, < gpet80ww Affected
lenovo thinkpad_t550_firmware >= 0, < n11et50w Affected
lenovo thinkpad_t560_firmware >= 0, < n1ket46w Affected

Frequently Asked Questions

What is CVE-2022-1107?

CVE-2022-1107 is a medium-severity vulnerability affecting lenovo thinkpad_11e_firmware. It was published on April 22, 2022 and has a CVSS 3.1 base score of 6.7 (MEDIUM).

How severe is CVE-2022-1107?

This vulnerability has a CVSS 3.1 base score of 6.7, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2022-1107?

Check the references section for vendor advisories and patches from lenovo. Update thinkpad_11e_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2022-1107?

CyberStrike's AI-powered security agents can automatically detect CVE-2022-1107 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.