Skip to content

[VULN] Security Alert for diagnostics #812

@my-local-testing-github-app

Description

@my-local-testing-github-app

Alert IDs:

  • 913542f5-dd2b-46c7-940d-2bab240af8ad
  • b9cdebc5-1828-4fbf-8869-e73db1aecd86
  • dea629f8-2db7-4bd1-bd0f-f54dd007d8dd
  • decc15eb-7689-4cad-8086-017cf13d3472

Vulnerabilities in diagnostics

Release: March19 release 2

Total Vulnerabilities: 4


1. CVE-2022-3698

Severity: MEDIUM (Score: 4.4)

Description:

A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to

1.3.1.2

and 

Lenovo Diagnostics versions prior to 4.45

that could allow a local user with administrative access to trigger a system crash.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2022-3698

Alert ID: 913542f5-dd2b-46c7-940d-2bab240af8ad


2. CVE-2022-0353

Severity: MEDIUM (Score: 4.4)

Description:

A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to

1.3.1.2

and 

Lenovo Diagnostics versions prior to 4.45

that could allow a local user with administrative access to trigger a system crash.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2022-0353

Alert ID: b9cdebc5-1828-4fbf-8869-e73db1aecd86


3. CVE-2020-8338

Severity: HIGH (Score: 7.8)

Description:
A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execute code on the system.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2020-8338

Alert ID: dea629f8-2db7-4bd1-bd0f-f54dd007d8dd


4. CVE-2022-3699

Severity: HIGH (Score: 7.8)

Description:

A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45

that could allow a local user to execute code with elevated privileges.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2022-3699

Alert ID: decc15eb-7689-4cad-8086-017cf13d3472


Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions