CVE-2023-25494: Lenovo Desktop Bios, Smart Edge Bios, Thinkstation BIOS

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables.

Affected products

  • Lenovo Desktop Bios, Smart Edge Bios, Thinkstation BIOS

Published 2024-04-05. Last modified 2026-06-17.