CVE-2026-10588
MEDIUMLenovo Yoga Pro 7 15IPH11 and Multiple Legion/IdeaPad BIOS - System Management Mode Memory Address Disclosure
Title source: llmDescription
A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://support.lenovo.com/us/en/product_security/LEN-220440
Scores
CVSS v3
4.4
EPSS
0.0011
EPSS Percentile
1.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-497
Status
published
Products (50)
Lenovo/IdeaPad 5 15ABA7 BIOS
< KACN29WW
Lenovo/IdeaPad Pro 5 16AGP11 BIOS
< T8CN19WW
Lenovo/IdeaPad Pro 5 16ASP10 BIOS
< R1CN24WW
Lenovo/IdeaPad Pro 5 16IAH10 BIOS
< PZCN27WW
Lenovo/IdeaPad Pro 5 16IMH9 BIOS
< MECN68WW
Lenovo/IdeaPad Pro 5 16IPH11 BIOS
< S4CN62WW
Lenovo/IdeaPad Pro 5 16IRH8 BIOS
< KZCN46WW
Lenovo/IdeaPad Slim 3 14ITN9 BIOS
< QUCN20WW
Lenovo/IdeaPad Slim 3 15AMN8 BIOS
< L1CN51WW
Lenovo/IdeaPad Slim 3 16ARP10 BIOS
< QBCN30WW
... and 40 more
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026