CVE-2023-4030

HIGH

ThinkPad P14s Gen 2-P15s Gen 2-T14 Gen 2-T15 Gen 2 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt.

References (1)

Core 1

Scores

CVSS v3 8.4
EPSS 0.0008
EPSS Percentile 23.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-636
Status published
Products (4)
lenovo/thinkpad_p14s_gen_2_firmware
lenovo/thinkpad_p15s_gen_2_firmware
lenovo/thinkpad_t14_gen_2_firmware
lenovo/thinkpad_t15_gen_2_firmware
Published Aug 17, 2023
Tracked Since Feb 18, 2026