5.5

CVE-2017-3740

In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LenovoActive Protection System Version1.00b
LenovoActive Protection System Version1.01b
LenovoActive Protection System Version1.20b
LenovoActive Protection System Version1.30b
LenovoActive Protection System Version1.33b
LenovoActive Protection System Version1.77.0.5
LenovoActive Protection System Version1.77.0.7
LenovoActive Protection System Version1.77.0.8
LenovoActive Protection System Version1.77.0.9
LenovoActive Protection System Version1.77.0.11
LenovoActive Protection System Version1.77.0.20
LenovoActive Protection System Version1.77.0.26
LenovoActive Protection System Version1.78.0.09
LenovoActive Protection System Version1.78.0.10
LenovoActive Protection System Version1.78.0.11
LenovoActive Protection System Version1.79.0.03
LenovoActive Protection System Version1.80.1.00
LenovoActive Protection System Version1.80.3.00
LenovoActive Protection System Version1.80.8.00
LenovoActive Protection System Version1.80.11.00
LenovoActive Protection System Version1.81.0.08
LenovoActive Protection System Version1.82.0.03
LenovoActive Protection System Version1.82.0.06
LenovoActive Protection System Version1.82.0.07
LenovoActive Protection System Version1.82.0.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.089
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C