6.8

CVE-2020-8320

An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

Data is provided by the National Vulnerability Database (NVD)
LenovoThinkpad 11e Yoga Gen 6 Firmware Version < 2020-07-10
   LenovoThinkpad 11e Yoga Gen 6 Version-
LenovoThinkpad 11e Firmware Version < 2020-07-10
   LenovoThinkpad 11e Version-
LenovoThinkpad Yoga 11e 3rd Gen Firmware Version < 2020-07-10
   LenovoThinkpad Yoga 11e 3rd Gen Version-
LenovoThinkpad Yoga 11e 4th Gen Firmware Version < 2020-07-10
   LenovoThinkpad Yoga 11e 4th Gen Version-
LenovoThinkpad Yoga 11e 5th Gen Firmware Version < 2020-07-10
   LenovoThinkpad Yoga 11e 5th Gen Version-
LenovoThinkpad 13 2nd Gen Firmware Version < 2020-07-10
   LenovoThinkpad 13 2nd Gen Version-
LenovoThinkpad 13 Firmware Version < 2020-07-10
   LenovoThinkpad 13 Version-
LenovoThinkpad A275 Firmware Version < 2020-07-10
   LenovoThinkpad A275 Version-
LenovoThinkpad A285 Firmware Version < 2020-07-10
   LenovoThinkpad A285 Version-
LenovoThinkpad A475 Firmware Version < 2020-07-10
   LenovoThinkpad A475 Version-
LenovoThinkpad A485 Firmware Version < 2020-07-10
   LenovoThinkpad A485 Version-
LenovoThinkpad E14 Firmware Version < 2020-07-10
   LenovoThinkpad E14 Version-
LenovoThinkpad E15 Firmware Version < 2020-07-10
   LenovoThinkpad E15 Version-
LenovoThinkpad R14 Firmware Version < 2020-07-10
   LenovoThinkpad R14 Version-
LenovoThinkpad S3 Gen 2 Firmware Version < 2020-07-10
   LenovoThinkpad S3 Gen 2 Version-
LenovoThinkpad E455 Firmware Version < 2020-07-10
   LenovoThinkpad E455 Version-
LenovoThinkpad E555 Firmware Version < 2020-07-10
   LenovoThinkpad E555 Version-
LenovoThinkpad E460 Firmware Version < 2020-07-10
   LenovoThinkpad E460 Version-
LenovoThinkpad E560 Firmware Version < 2020-07-10
   LenovoThinkpad E560 Version-
LenovoThinkpad E465 Firmware Version < 2020-07-10
   LenovoThinkpad E465 Version-
LenovoThinkpad E565 Firmware Version < 2020-07-10
   LenovoThinkpad E565 Version-
LenovoThinkpad E470 Firmware Version < 2020-07-10
   LenovoThinkpad E470 Version-
LenovoThinkpad E570 Firmware Version < 2020-07-10
   LenovoThinkpad E570 Version-
LenovoThinkpad E475 Firmware Version < 2020-07-10
   LenovoThinkpad E475 Version-
LenovoThinkpad E575 Firmware Version < 2020-07-10
   LenovoThinkpad E575 Version-
LenovoThinkpad E480 Firmware Version < 2020-07-10
   LenovoThinkpad E480 Version-
LenovoThinkpad E580 Firmware Version < 2020-07-10
   LenovoThinkpad E580 Version-
LenovoThinkpad E485 Firmware Version < 2020-07-10
   LenovoThinkpad E485 Version-
LenovoThinkpad E585 Firmware Version < 2020-07-10
   LenovoThinkpad E585 Version-
LenovoThinkpad E490s Firmware Version < 2020-07-10
   LenovoThinkpad E490s Version-
LenovoThinkpad S3 Firmware Version < 2020-07-10
   LenovoThinkpad S3 Version-
LenovoThinkpad E490 Firmware Version < 2020-07-10
   LenovoThinkpad E490 Version-
LenovoThinkpad E590 Firmware Version < 2020-07-10
   LenovoThinkpad E590 Version-
LenovoThinkpad R490 Firmware Version < 2020-07-10
   LenovoThinkpad R490 Version-
LenovoThinkpad R590 Firmware Version < 2020-07-10
   LenovoThinkpad R590 Version-
LenovoThinkpad L13 Firmware Version < 2020-07-10
   LenovoThinkpad L13 Version-
LenovoThinkpad L1415 Firmware Version < 2020-07-10
   LenovoThinkpad L1415 Version-
LenovoThinkpad L380 Firmware Version < 2020-07-10
   LenovoThinkpad L380 Version-
LenovoThinkpad S3 3rd Gen Firmware Version < 2020-07-10
   LenovoThinkpad S3 3rd Gen Version-
LenovoThinkpad L380 Yoga Firmware Version < 2020-07-10
   LenovoThinkpad L380 Yoga Version-
LenovoThinkpad S2 Yoga 3rd Gen Firmware Version < 2020-07-10
   LenovoThinkpad S2 Yoga 3rd Gen Version-
LenovoThinkpad L390 Yoga Firmware Version < 2020-07-10
   LenovoThinkpad L390 Yoga Version-
LenovoThinkpad S2 Yoga 4th Gen Firmware Version < 2020-07-10
   LenovoThinkpad S2 Yoga 4th Gen Version-
LenovoThinkpad L460 Firmware Version < 2020-07-10
   LenovoThinkpad L460 Version-
LenovoThinkpad L470 Firmware Version < 2020-07-10
   LenovoThinkpad L470 Version-
LenovoThinkpad L480 Firmware Version < 2020-07-10
   LenovoThinkpad L480 Version-
LenovoThinkpad L580 Firmware Version < 2020-07-10
   LenovoThinkpad L580 Version-
LenovoThinkpad L490 Firmware Version < 2020-07-10
   LenovoThinkpad L490 Version-
LenovoThinkpad L590 Firmware Version < 2020-07-10
   LenovoThinkpad L590 Version-
LenovoThinkpad L560 Firmware Version < 2020-07-03
   LenovoThinkpad L560 Version-
LenovoThinkpad L570 Firmware Version < 2020-07-10
   LenovoThinkpad L570 Version-
LenovoThinkpad P1 Firmware Version < n2eet46w
   LenovoThinkpad P1 Version-
LenovoThinkpad P43s Firmware Version < n2iet87w
   LenovoThinkpad P43s Version-
LenovoThinkpad P50 Firmware Version < 2020-07-17
   LenovoThinkpad P50 Version-
LenovoThinkpad P50s Firmware Version < 2020-07-24
   LenovoThinkpad P50s Version-
LenovoThinkpad P51 Firmware Version < 2020-07-03
   LenovoThinkpad P51 Version-
LenovoThinkpad P51s Firmware Version < 2020-07-03
   LenovoThinkpad P51s Version-
LenovoThinkpad P52 Firmware Version < n2cet51w
   LenovoThinkpad P52 Version-
LenovoThinkpad P52s Firmware Version < 2020-07-03
   LenovoThinkpad P52s Version-
LenovoThinkpad P53 Firmware Version < n2net37w
   LenovoThinkpad P53 Version-
LenovoThinkpad P53s Firmware Version < n2iet87w
   LenovoThinkpad P53s Version-
LenovoThinkpad P70 Firmware Version < 2020-07-17
   LenovoThinkpad P70 Version-
LenovoThinkpad P71 Firmware Version <= 2020-07-17
   LenovoThinkpad P71 Version-
LenovoThinkpad P72 Firmware Version < n2cet51w
   LenovoThinkpad P72 Version-
LenovoThinkpad P73 Firmware Version < n2net37w
   LenovoThinkpad P73 Version-
LenovoThinkpad S5 2nd Gen Firmware Version < 2020-07-10
   LenovoThinkpad S5 2nd Gen Version-
LenovoThinkpad S5 Firmware Version < 2020-07-10
   LenovoThinkpad S5 Version-
LenovoThinkpad E560p Firmware Version < 2020-07-10
   LenovoThinkpad E560p Version-
LenovoThinkpad T25 Firmware Version < n1qet87w
   LenovoThinkpad T25 Version-
LenovoThinkpad T460 Firmware Version < 2020-07-10
   LenovoThinkpad T460 Version-
LenovoThinkpad T460p Firmware Version < 2020-07-10
   LenovoThinkpad T460p Version-
LenovoThinkpad T460s Firmware Version < 2020-06-19
   LenovoThinkpad T460s Version-
LenovoThinkpad T470 Firmware Version < n1qet87w
   LenovoThinkpad T470 Version-
LenovoThinkpad T470p Firmware Version < 2020-07-10
   LenovoThinkpad T470p Version-
LenovoThinkpad T470s Firmware Version < n1wet58w
   LenovoThinkpad T470s Version-
LenovoThinkpad T480 Firmware Version < n24et56w
   LenovoThinkpad T480 Version-
LenovoThinkpad T480s Firmware Version < n22et62w
   LenovoThinkpad T480s Version-
LenovoThinkpad T490 Firmware Version < n2iet87w
   LenovoThinkpad T490 Version-
LenovoThinkpad T490s Firmware Version < n2jet87w
   LenovoThinkpad T490s Version-
LenovoThinkpad T560 Firmware Version < 2020-07-24
   LenovoThinkpad T560 Version-
LenovoThinkpad T570 Firmware Version < 2020-07-03
   LenovoThinkpad T570 Version-
LenovoThinkpad T580 Firmware Version < 2020-07-03
   LenovoThinkpad T580 Version-
LenovoThinkpad T590 Firmware Version < n2iet87w
   LenovoThinkpad T590 Version-
LenovoThinkpad X1 Carbon Firmware Version < n1met60w
   LenovoThinkpad X1 Carbon Version-
LenovoThinkpad X1 Yoga Firmware Version < 2020-07-17
   LenovoThinkpad X1 Yoga Version-
LenovoThinkpad X1 Extreme Firmware Version < n2oet43w
   LenovoThinkpad X1 Extreme Version-
LenovoThinkpad X1 Tablet Firmware Version < 2020-07-24
   LenovoThinkpad X1 Tablet Version-
LenovoThinkpad X1 Yoga Firmware Version < 2020-07-17
   LenovoThinkpad X1 Yoga Version-
LenovoThinkpad X260 Firmware Version < 2020-07-10
   LenovoThinkpad X260 Version-
LenovoThinkpad X270 Firmware Version < 2020-07-10
   LenovoThinkpad X270 Version-
LenovoThinkpad X280 Firmware Version < n20et52w
   LenovoThinkpad X280 Version-
LenovoThinkpad X380 Yoga Firmware Version < 2020-07-10
   LenovoThinkpad X380 Yoga Version-
LenovoThinkpad X390 Firmware Version < 2020-07-07
   LenovoThinkpad X390 Version-
LenovoThinkpad X390 Yoga Firmware Version < 2020-06-24
   LenovoThinkpad X390 Yoga Version-
LenovoThinkpad X395 Firmware Version < 2020-07-10
   LenovoThinkpad X395 Version-
LenovoThinkpad Yoga 260 Firmware Version < 2020-07-07
   LenovoThinkpad Yoga 260 Version-
LenovoThinkpad S1 Firmware Version < 2020-07-07
   LenovoThinkpad S1 Version-
LenovoThinkpad Yoga 370 Firmware Version < 2020-07-10
   LenovoThinkpad Yoga 370 Version-
LenovoThinkpad S1 3rd Firmware Version < 2020-07-10
   LenovoThinkpad S1 3rd Version-
LenovoThinkpad T495 Firmware Version < 2020-07-10
   LenovoThinkpad T495 Version-
LenovoThinkpad T495s Firmware Version < 2020-07-10
   LenovoThinkpad T495s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.112
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
psirt@lenovo.com 6.4 0.5 5.9
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

CWE-489 Active Debug Code

The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.