7
CVE-2018-9069
- EPSS 0.21%
- Veröffentlicht 02.10.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:54
- Quelle psirt@lenovo.com
- Teams Watchlist Login
- Unerledigt Login
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ 310s-14isk Firmware Version < 1.15
Hp ≫ 320-15ikbra Firmware Version < 6jcn24ww
Hp ≫ 320-15ikbrn Firmware Version < 6jcn24ww
Hp ≫ 320-15ikbrn Touch Firmware Version < 6jcn24ww
Hp ≫ 320-17ikbrn Version < 2.09
Hp ≫ 320s-14ikb Version < 2.09
Hp ≫ 320s-15ikb Firmware Version < 2.09
Hp ≫ 320s-15isk Firmware Version < 2wcn38ww
Hp ≫ 510s-14isk Firmware Version < 1.15
Hp ≫ 520-15ikbrn Firmware Version < 6jcn26ww
Hp ≫ 520s-14ikb Firmware Version < 2.09
Hp ≫ 710s Plus-13ikb 16g Firmware Version < 2.55
Hp ≫ 710s Plus-3ikb Firmware Version < 2.55
Hp ≫ Xiaoxinair13ikbpro Firmware Version < 2.55
Hp ≫ 710s Plus Touch-13ikb Firmware Version < 2.55
Hp ≫ 720s-13ikb Firmware Version < 5scn38ww
Hp ≫ B320-14ikb Firmware Version-
Lenovo ≫ E42-80 Firmware Version < 2wcn38ww
Lenovo ≫ E52-80 Firmware Version < 2wcn38ww
Hp ≫ Flex 4-1470 Firmware Version < 1.15
Hp ≫ Flex 5-1470 Firmware Version < 2.09
Hp ≫ Flex 5-1570 Firmware Version < 2.09
Hp ≫ Ideapad 2in1 14 Firmware Version-
Hp ≫ Lenovo Ideapad 320-14ikb(i+a) Firmware Version-
Hp ≫ Lenovo Ideapad 320-14ikb(i+n) Firmware Version-
Hp ≫ Lenovo Ideapad 320-15abr Firmware Version-
Hp ≫ Lenovo Ideapad 320-15ikb(i+n) Firmware Version-
Hp ≫ Lenovo Ideapad 320s-14ikbr Firmware Version-
Hp ≫ Lenovo Ideapad 320s-15ikbr Firmware Version-
Hp ≫ Lenovo Ideapad 520s-14ikbr Firmware Version-
Hp ≫ Lenovo Ideapad 720s-14ikb Firmware Version < 6jcn26ww
Hp ≫ Lenovo Ideapad Flex 5-1470 Firmware Version < 6jcn26ww
Hp ≫ Lenovo Ideapad Flex 5-1570 Firmware Version < 6jcn26ww
Hp ≫ Lenovo Ideapad Y520-15ikbn Firmware Version-
Hp ≫ Lenovo Tianyi 310-14ikb Firmware Version-
Hp ≫ Lenovo Tianyi 310-15ikb Firmware Version-
Hp ≫ Lenovo Y520-15ikba Firmware Version < 5jcn25ww
Hp ≫ Lenovo Y520-15ikbm Firmware Version < 5jcn25ww
Hp ≫ Lenovo Yoga 520-14ikb Firmware Version < 6jcn26ww
Hp ≫ Lenovo Yoga 520-15ikb Firmware Version < 6jcn26ww
Hp ≫ Miix 720-12ikb Version < 3scn66ww
Hp ≫ Nano110-14ikb Firmware Version-
Hp ≫ Nano110-15ikb Firmware Version < 5xcn24ww
Hp ≫ Rescuer R720-15ikbm Firmware Version < 5xcn24ww
Hp ≫ Rescuer Y520-15ikbm Firmware Version < 5xcn24ww
Lenovo ≫ V310-14ikb Firmware Version < 2wcn38ww
Lenovo ≫ V310-14isk Firmware Version < 4.07
Lenovo ≫ V310-15ikb Firmware Version < 2wcn38ww
Lenovo ≫ V310-15isk Firmware Version < 0zcn47ww
Hp ≫ V330-14ikb Firmware Version < 4.07
Hp ≫ V330-14isk Firmware Version < 4.07
Lenovo ≫ V510-14ikb Firmware Version < 2wcn38ww
Lenovo ≫ V510-15ikb Firmware Version < 2wcn38ww
Hp ≫ Yoga 310-11iap Firmware Version < 6.7
Hp ≫ Yoga 510-14isk Firmware Version < 1.15
Hp ≫ Yoga 720-13ikb Firmware Version < 2.05
Hp ≫ Yoga 720-13ikbr Firmware Version < 2.07
Hp ≫ Yoga 720-15ikb Firmware Version < 2.05
Hp ≫ Lenovo V720-14 Firmware Version < 2.12
Hp ≫ 7000 U42 Firmware Version < 2.09
Hp ≫ 7000-15 U42 Firmware Version < 2.09
Hp ≫ R720-15ikba Firmware Version < 5jcn25ww
Hp ≫ Y520-15ikba Firmware Version < 5jcn25ww
Hp ≫ R720-15ikbn Firmware Version < 4gcn38ww
Hp ≫ Y520-15ikbn Firmware Version < 4gcn38ww
Hp ≫ Y720-15ikb Firmware Version < 4gcn38ww
Hp ≫ Lenovo Y720-15ikb Firmware Version < 4gcn38ww
Hp ≫ E43-80 Kbl Firmware Version < 4.07
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.21% | 0.406 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 0.7 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
|
nvd@nist.gov | 7 | 6.8 | 7.8 |
AV:N/AC:M/Au:S/C:N/I:P/A:C
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.