¡¾Â©¶´Í¨¸æ¡¿Lenovo ThinkPad BIOS¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2023-01-05

 

0x00 ©¶´¸ÅÊö

1ÔÂ3ÈÕ£¬Lenovo£¨ÁªÏ룩Ðû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËThinkPad X13s BIOSÖеĶà¸öÄþ¾²Â©¶´£¬µ±µØÓû§¿ÉÀûÓÃÕâЩ©¶´µ¼ÖÂÄÚ´æË𻵻òÃô¸ÐÐÅϢй¶¡£

 

0x01 ©¶´ÏêÇé

LenovoÊÇÒ»¼ÒÈ«ÇòÖªÃûµÄICT¿Æ¼¼ÆóÒµ£¬Ò²ÊÇÈ«ÇòÖÇÄÜÉ豸µÄÁìµ¼³§ÉÌÖ®Ò»¡£

±¾´ÎThinkPad X13s BIOS¸üÐÂÖй²ÐÞ¸´ÁËÈçÏ©¶´£º

CVE-ID

ÀàÐÍ

ÆÀ·Ö

ÊÜÓ°Ïì²úÎï/×é¼þ

ÃèÊö

CVE-2022-40516

»ùÓÚ¶ÑÕ»µÄ»º³åÇøÒç³öµ¼ÖÂÄÚ´æËð»µ

8.4

Qualcomm BIOS

µ±µØÓû§¿ÉÀûÓÃÕâЩ©¶´µ¼ÖÂÄÚ´æË𻵡¢¾Ü¾ø·þÎñ»òÈÎÒâ´úÂëÖ´ÐС£

CVE-2022-40517

CVE-2022-40520

CVE-2022-40518

»º³åÇø¹ý¶È¶ÁÈ¡

6.8

Qualcomm BIOS

µ±µØÓû§¿ÉÀûÓÃÕâЩ©¶´µ¼ÖÂÐÅϢй¶¡£

CVE-2022-40519

CVE-2022-4432¡¢CVE-2022-4433¡¢CVE-2022-4434¡¢CVE-2022-4435

»º³åÇø¹ý¶È¶ÁÈ¡

None

ThinkPad X13s BIOS

µ±µØÓû§¿ÉÀûÓÃÕâЩ©¶´µ¼ÖÂÐÅϢй¶¡£

 

Ó°Ï췶Χ

ThinkPad X13s BIOS °æ±¾ < 1.47 (N3HET75W)

 

0x02 Äþ¾²½¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´£¬Lenovo ThinkPad X13sÓû§¿É½«BIOS¸üе½1.47 (N3HET75W)°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://pcsupport.lenovo.com/us/en/products/laptops-and-netbooks/thinkpad-x-series-laptops/thinkpad-x13s-type-21bx-21by/downloads/ds556845-bios-update-utility-bootable-cd-for-windows-11-thinkpad-x13s-gen-1-type-21bx-21by?category=BIOS%2FUEFI

×¢£ºCVE-2022-40516 - CVE-2022-40520Ò²Ó°ÏìÁËÁªÏë ThinkPad X13s Ìõ¼Ç±¾µçÄÔ£¬ÕâЩ©¶´Ò²ÔÚBIOS°æ±¾ 1.47 (N3HET75W)ÖÐÐÞ¸´¡£

 

0x03 ²Î¿¼Á´½Ó

https://support.lenovo.com/us/en/product_security/LEN-103709

https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2023-bulletin.html

https://thehackernews.com/2023/01/qualcomm-chipsets-and-lenovo-bios-get.html


0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2023-01-05

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

 

¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png