6.7

CVE-2020-8353

Exploit

Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.

Data is provided by the National Vulnerability Database (NVD)
LenovoThinkcentre M80t Firmware Version < 2020-08-10
   LenovoThinkcentre M80t Version-
LenovoThinkcentre M80s Firmware Version < 2020-08-10
   LenovoThinkcentre M80s Version-
LenovoThinkcentre M90t Firmware Version < 2020-08-10
   LenovoThinkcentre M90t Version-
LenovoThinkcentre M90s Firmware Version < 2020-08-10
   LenovoThinkcentre M90s Version-
LenovoThinkcentre M910z Firmware Version < 2020-08-10
   LenovoThinkcentre M910z Version-
LenovoThinkcentre M920s Firmware Version < 2020-08-10
   LenovoThinkcentre M920s Version-
LenovoThinkcentre M920t Firmware Version < 2020-08-10
   LenovoThinkcentre M920t Version-
LenovoThinkcentre M920q Firmware Version < 2020-08-10
   LenovoThinkcentre M920q Version-
LenovoThinkcentre M920z Firmware Version < 2020-08-10
   LenovoThinkcentre M920z Version-
LenovoThinkstation P330t Firmware Version < 2020-08-10
   LenovoThinkstation P330t Version-
LenovoThinkstation P330s Firmware Version < 2020-08-10
   LenovoThinkstation P330s Version-
LenovoThinkstation P330 Tiny Firmware Version < 2020-08-10
   LenovoThinkstation P330 Tiny Version-
LenovoThinkstation P340t Firmware Version < 2020-08-10
   LenovoThinkstation P340t Version-
LenovoThinkstation P340s Firmware Version < 2020-08-10
   LenovoThinkstation P340s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.122
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H