Cyber Resilience

CVE-2023-4030

High

Published: 17 August 2023

Published
17 August 2023
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0008 23.7th percentile
Risk Priority 17 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2023-4030 is a high-severity Failing Open (CWE-636) vulnerability in Lenovo Thinkpad T15 Gen 2 Firmware. Its CVSS base score is 8.4 (High).

Operationally, ranked at the 23.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

lenovo
thinkpad t15 gen 2 firmware
all versions
lenovo
thinkpad p14s gen 2 firmware
all versions
lenovo
thinkpad p15s gen 2 firmware
all versions
lenovo
thinkpad t14 gen 2 firmware
all versions

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-636

Ensures audit logging continues on primary failure instead of failing open with no logging capability.

addresses: CWE-636

Supports failing securely by requiring alerts and configurable actions (e.g., shutdown) when the audit mechanism fails instead of continuing without it.

addresses: CWE-636

Entering safe mode when conditions are detected prevents failing open and continuing normal operation in a potentially exploitable state.

addresses: CWE-636

Ensures security functions remain enforced via alternatives instead of defaulting to an insecure state when the primary means fails.

addresses: CWE-636

Fail-safe-defaults principle prevents systems from failing open.

addresses: CWE-636

Directly requires transition to a known (secure) state on failure, preventing fail-open behavior.

addresses: CWE-636

Standby components and explicit exchange criteria enforce a controlled, secure failover instead of failing open.

addresses: CWE-636

Directly implements fail-safe (fail-closed/secure) behavior on indicated failures, preventing the system from defaulting to an insecure open state.

References