3.3

CVE-2019-6156

In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo510-15ikl Firmware Version-
   Lenovo510-15ikl Version-
Lenovo510s-08ikl Firmware Version-
   Lenovo510s-08ikl Version-
LenovoIdeacentre 510-15icb Firmware Version < o3qkt32a
   LenovoIdeacentre 510-15icb Version-
LenovoIdeacentre 510a-15icb Firmware Version < o3qkt32a
   LenovoIdeacentre 510a-15icb Version-
LenovoIdeacentre 700 Firmware Version < fwkt9aa
   LenovoIdeacentre 700 Version-
LenovoIdeacentre 720-18icb Firmware Version < o3qkt32a
   LenovoIdeacentre 720-18icb Version-
LenovoLegion C530-19icb Firmware Version < o3lkt20a
   LenovoLegion C530-19icb Version-
LenovoLegion C730-19ico Firmware Version < o3nkt20a
   LenovoLegion C730-19ico Version-
LenovoLegion T530-28icb Firmware Version < o3lkt20a
   LenovoLegion T530-28icb Version-
LenovoLegion T730-28ico Firmware Version < o3nkt20a
   LenovoLegion T730-28ico Version-
LenovoLegion Y520t Z370 Firmware Version-
   LenovoLegion Y520t Z370 Version-
LenovoLegion Y720 Tower Firmware Version-
   LenovoLegion Y720 Tower Version-
LenovoLegion Y920 Tower Firmware Version-
   LenovoLegion Y920 Tower Version-
LenovoLenovo 63 Firmware Version-
   LenovoLenovo 63 Version-
LenovoH50-30g Desktop Firmware Version-
   LenovoH50-30g Desktop Version-
LenovoM4500 Firmware Version-
   LenovoM4500 Version-
LenovoM4500 Id Firmware Version-
   LenovoM4500 Id Version-
LenovoM4550 Id Firmware Version-
   LenovoM4550 Id Version-
Lenovo530s-07icb Firmware Version-
   Lenovo530s-07icb Version-
LenovoQitian 4500 Firmware Version-
   LenovoQitian 4500 Version-
LenovoQitian B4550 Firmware Version-
   LenovoQitian B4550 Version-
LenovoQitian B4650 Firmware Version-
   LenovoQitian B4650 Version-
LenovoQitian M4550 Firmware Version-
   LenovoQitian M4550 Version-
LenovoQitian M4600 Firmware Version-
   LenovoQitian M4600 Version-
LenovoQitian M4650 Firmware Version-
   LenovoQitian M4650 Version-
LenovoQt M410 Firmware Version-
   LenovoQt M410 Version-
LenovoQt B415 Firmware Version-
   LenovoQt B415 Version-
LenovoQt M415 Firmware Version-
   LenovoQt M415 Version-
LenovoThinkcentre E73s Firmware Version-
   LenovoThinkcentre E73s Version-
LenovoThinkcentre E74 Firmware Version-
   LenovoThinkcentre E74 Version-
LenovoThinkcentre E74s Firmware Version-
   LenovoThinkcentre E74s Version-
LenovoThinkcentre E75t Firmware Version-
   LenovoThinkcentre E75t Version-
LenovoThinkcentre E75s Firmware Version-
   LenovoThinkcentre E75s Version-
LenovoThinkcentre E93 (sff) Firmware Version < fbktd5a
   LenovoThinkcentre E93 (sff) Version-
LenovoThinkcentre E93 (twr) Firmware Version < fbktd5a
   LenovoThinkcentre E93 (twr) Version-
LenovoThinkcentre M610 Firmware Version < m1akt3fa
   LenovoThinkcentre M610 Version-
LenovoThinkcentre M6500t Firmware Version < fbktd5a
   LenovoThinkcentre M6500t Version-
LenovoThinkcentre M6500s Firmware Version < fbktd5a
   LenovoThinkcentre M6500s Version-
LenovoThinkcentre M6600 Firmware Version < fwkt9aa
   LenovoThinkcentre M6600 Version-
LenovoThinkcentre M6600q Firmware Version < fwkt9aa
   LenovoThinkcentre M6600q Version-
LenovoThinkcentre M6600t Firmware Version < fwkt9aa
   LenovoThinkcentre M6600t Version-
LenovoThinkcentre M6600s Firmware Version < fwkt9aa
   LenovoThinkcentre M6600s Version-
LenovoThinkcentre M700q Firmware Version < fwkt9aa
   LenovoThinkcentre M700q Version-
LenovoThinkcentre M700t Firmware Version-
   LenovoThinkcentre M700t Version-
LenovoThinkcentre M700s Firmware Version-
   LenovoThinkcentre M700s Version-
LenovoThinkcentre M710e Firmware Version-
   LenovoThinkcentre M710e Version-
LenovoThinkcentre M710q Firmware Version < m1akt3fa
   LenovoThinkcentre M710q Version-
LenovoThinkcentre M710t Firmware Version-
   LenovoThinkcentre M710t Version-
LenovoThinkcentre M710s Firmware Version-
   LenovoThinkcentre M710s Version-
LenovoThinkcentre M720q Firmware Version < m1ukt33a
   LenovoThinkcentre M720q Version-
LenovoThinkcentre M720t Firmware Version <= m1ukt33a
   LenovoThinkcentre M720t Version-
LenovoThinkcentre M720s Firmware Version < m1ukt33a
   LenovoThinkcentre M720s Version-
LenovoThinkcentre M73p Firmware Version < fbktd5a
   LenovoThinkcentre M73p Version-
LenovoThinkcentre M800 Firmware Version < fwkt9aa
   LenovoThinkcentre M800 Version-
LenovoThinkcentre M83 (sff) Firmware Version < fbktd5a
   LenovoThinkcentre M83 (sff) Version-
LenovoThinkcentre M83 (tiny) Firmware Version < fbktd5a
   LenovoThinkcentre M83 (tiny) Version-
LenovoThinkcentre M83 (twr) Firmware Version < fbktd5a
   LenovoThinkcentre M83 (twr) Version-
LenovoThinkcentre M8500t Firmware Version < fbktd5a
   LenovoThinkcentre M8500t Version-
LenovoThinkcentre M8500s Firmware Version < fbktd5a
   LenovoThinkcentre M8500s Version-
LenovoThinkcentre M8600t Firmware Version < fwkt9aa
   LenovoThinkcentre M8600t Version-
LenovoThinkcentre M8600s Firmware Version < fwkt9aa
   LenovoThinkcentre M8600s Version-
LenovoThinkcentre M900 Firmware Version < fwkt9aa
   LenovoThinkcentre M900 Version-
LenovoThinkcentre M910t Firmware Version < m1akt3fa
   LenovoThinkcentre M910t Version-
LenovoThinkcentre M910s Firmware Version < m1akt3fa
   LenovoThinkcentre M910s Version-
LenovoThinkcentre M910q Firmware Version < m1akt3fa
   LenovoThinkcentre M910q Version-
LenovoThinkcentre M910x Firmware Version < m1akt3fa
   LenovoThinkcentre M910x Version-
LenovoThinkcentre M920q Firmware Version < m1ukt33a
   LenovoThinkcentre M920q Version-
LenovoThinkcentre M920x Firmware Version < m1ukt33a
   LenovoThinkcentre M920x Version-
LenovoThinkcentre M920t Firmware Version < m1ukt33a
   LenovoThinkcentre M920t Version-
LenovoThinkcentre M920s Firmware Version < m1ukt33a
   LenovoThinkcentre M920s Version-
LenovoThinkcentre M93 Firmware Version < fbktd5a
   LenovoThinkcentre M93 Version-
LenovoThinkcentre M93p (sff) Firmware Version < fbktd5a
   LenovoThinkcentre M93p (sff) Version-
LenovoThinkcentre M93p (twr) Firmware Version < fbktd5a
   LenovoThinkcentre M93p (twr) Version-
LenovoThinkcentre M93p Tiny Firmware Version < fbktd5a
   LenovoThinkcentre M93p Tiny Version-
LenovoThinkcentre S510 Firmware Version-
   LenovoThinkcentre S510 Version-
LenovoV520s-08ikl Firmware Version-
   LenovoV520s-08ikl Version-
LenovoV520t-15ikl Firmware Version-
   LenovoV520t-15ikl Version-
LenovoYangtian Afh110 Firmware Version-
   LenovoYangtian Afh110 Version-
LenovoYangtian Afh81 Firmware Version-
   LenovoYangtian Afh81 Version-
LenovoYangtian Afq150 Firmware Version < fwkt9aa
   LenovoYangtian Afq150 Version-
LenovoYangtian Mc H110 Firmware Version-
   LenovoYangtian Mc H110 Version-
LenovoYangtian Mc H81 Firmware Version-
   LenovoYangtian Mc H81 Version-
LenovoYta8900f Firmware Version < fwkt9aa
   LenovoYta8900f Version-
LenovoAio 910-27ish Firmware Version < o37kt13a
   LenovoAio 910-27ish Version-
LenovoAio Y910-27ish Firmware Version-
   LenovoAio Y910-27ish Version-
LenovoAio300-23isu(c5130) Firmware Version < o1lkt46a
   LenovoAio300-23isu(c5130) Version-
LenovoAio520-22ikl Firmware Version-
   LenovoAio520-22ikl Version-
LenovoAio520-22iku Firmware Version-
   LenovoAio520-22iku Version-
LenovoAio520-24ikl Firmware Version-
   LenovoAio520-24ikl Version-
LenovoAio520-24iku Firmware Version-
   LenovoAio520-24iku Version-
LenovoAio520-27ikl Firmware Version-
   LenovoAio520-27ikl Version-
LenovoIdeacentre 520s-23iku Firmware Version < o34kt23a
   LenovoIdeacentre 520s-23iku Version-
LenovoIdeacentre 730s-24ikb Firmware Version < o3wkt15a
   LenovoIdeacentre 730s-24ikb Version-
LenovoQt A7400 Firmware Version-
   LenovoQt A7400 Version-
LenovoThinkcenter M700z Firmware Version-
   LenovoThinkcenter M700z Version-
LenovoThinkcenter M800z Firmware Version-
   LenovoThinkcenter M800z Version-
LenovoThinkcentre E74z Firmware Version-
   LenovoThinkcentre E74z Version-
LenovoThinkcentre E95z Firmware Version < m1lkt20a
   LenovoThinkcentre E95z Version-
LenovoThinkcentre E96z Firmware Version < m26kt11a
   LenovoThinkcentre E96z Version-
LenovoThinkcentre M700z Firmware Version-
   LenovoThinkcentre M700z Version-
LenovoThinkcentre M800z Firmware Version-
   LenovoThinkcentre M800z Version-
LenovoThinkcentre M810z Firmware Version-
   LenovoThinkcentre M810z Version-
LenovoThinkcentre M818z Firmware Version-
   LenovoThinkcentre M818z Version-
LenovoThinkcentre M820z Firmware Version-
   LenovoThinkcentre M820z Version-
LenovoThinkcentre M900z Firmware Version-
   LenovoThinkcentre M900z Version-
LenovoThinkcentre M910z Firmware Version-
   LenovoThinkcentre M910z Version-
LenovoThinkcentre M920z Firmware Version-
   LenovoThinkcentre M920z Version-
LenovoV310z(yt S3150) Firmware Version < m18kt25a
   LenovoV310z(yt S3150) Version-
LenovoV410z(yt S4250) Firmware Version < m17kt41a
   LenovoV410z(yt S4250) Version-
LenovoV510z (yt S5250) Firmware Version < m1dkt26a
   LenovoV510z (yt S5250) Version-
LenovoV530-22icb(yt S4350) Firmware Version < m20kt38a
   LenovoV530-22icb(yt S4350) Version-
LenovoV530-24icb(yt S5350) Firmware Version < m20kt38a
   LenovoV530-24icb(yt S5350) Version-
Lenovo330-14igm Firmware Version < 7xcn30ww
   Lenovo330-14igm Version-
Lenovo330-15igm Firmware Version < 7xcn30ww
   Lenovo330-15igm Version-
LenovoThinkpad E480 Firmware Version < r0pet54w
   LenovoThinkpad E480 Version-
LenovoThinkpad E580 Firmware Version < r0pet54w
   LenovoThinkpad E580 Version-
LenovoThinkpad E570p Firmware Version < r0met46w
   LenovoThinkpad E570p Version-
LenovoThinkpad S5 Firmware Version < r0met46w
   LenovoThinkpad S5 Version-
LenovoThinkpad L480 Firmware Version < r0qet54w
   LenovoThinkpad L480 Version-
LenovoThinkpad L580 Firmware Version < r0qet54w
   LenovoThinkpad L580 Version-
LenovoThinkpad S5 Firmware Version < r09et70w
   LenovoThinkpad S5 Version-
LenovoThinkpad E560p Firmware Version < r09et70w
   LenovoThinkpad E560p Version-
LenovoThinkpad T460 Firmware Version < r06et66w
   LenovoThinkpad T460 Version-
LenovoThinkpad T460p Firmware Version < r07et88w
   LenovoThinkpad T460p Version-
LenovoThinkpad X260 Firmware Version < r02et70w
   LenovoThinkpad X260 Version-
LenovoThinkpad X380 Yoga Firmware Version < r0set42w
   LenovoThinkpad X380 Yoga Version-
LenovoThinkstation E32 Firmware Version < fbktd5a
   LenovoThinkstation E32 Version-
LenovoThinkstation P300 Firmware Version < fbktd5a
   LenovoThinkstation P300 Version-
LenovoThinkstation P310 Firmware Version-
   LenovoThinkstation P310 Version-
LenovoThinkstation P318 Firmware Version < m1akt3fa
   LenovoThinkstation P318 Version-
LenovoThinkstation P320 Firmware Version < s06kt40a
   LenovoThinkstation P320 Version-
LenovoThinkstation P320 Tiny Firmware Version < m1akt3fa
   LenovoThinkstation P320 Tiny Version-
LenovoThinkstation P330 Firmware Version < m1vkt34a
   LenovoThinkstation P330 Version-
LenovoThinkstation P330 Tiny Firmware Version < m1ukt33a
   LenovoThinkstation P330 Tiny Version-
LenovoThinkstation P410 Firmware Version-
   LenovoThinkstation P410 Version-
LenovoThinkstation P500 Firmware Version-
   LenovoThinkstation P500 Version-
LenovoThinkstation P510 Firmware Version-
   LenovoThinkstation P510 Version-
LenovoThinkstation P520 Firmware Version-
   LenovoThinkstation P520 Version-
LenovoThinkstation P700 Firmware Version-
   LenovoThinkstation P700 Version-
LenovoThinkstation P710 Firmware Version-
   LenovoThinkstation P710 Version-
LenovoThinkstation P720 Firmware Version-
   LenovoThinkstation P720 Version-
LenovoThinkstation P900 Firmware Version-
   LenovoThinkstation P900 Version-
LenovoThinkstation P910 Firmware Version-
   LenovoThinkstation P910 Version-
LenovoThinkstation P920 Firmware Version-
   LenovoThinkstation P920 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.097
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.3 1.8 1.4
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
CWE-667 Improper Locking

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.