6.7

CVE-2021-3452

A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Data is provided by the National Vulnerability Database (NVD)
LenovoBios Version-
   LenovoThinkpad 11e 3rd Gen Version-
   LenovoThinkpad 11e 4th Gen Version-
   LenovoThinkpad 11e 5th Gen Version-
   LenovoThinkpad 11e Yoga Gen 6 Version-
   LenovoThinkpad 13 Gen 2 Version-
   LenovoThinkpad E14 Gen 2 Version-
   LenovoThinkpad E15 Gen 2 Version-
   LenovoThinkpad L13 Version-
   LenovoThinkpad L13 Gen 2 Version-
   LenovoThinkpad L13 Yoga Version-
   LenovoThinkpad L13 Yogo Gen 2 Version-
   LenovoThinkpad L14 Version-
   LenovoThinkpad L14 Gen 2 Version-
   LenovoThinkpad L15 Version-
   LenovoThinkpad L15 Gen 2 Version-
   LenovoThinkpad L380 Version-
   LenovoThinkpad L380 Yoga Version-
   LenovoThinkpad L390 Version-
   LenovoThinkpad L390 Yoga Version-
   LenovoThinkpad T460 Version-
   LenovoThinkpad X12 Detachable Gen 1 Version-
   LenovoThinkpad X260 Version-
   LenovoThinkpad X380 Yoga Version-
   LenovoThinkpad Yoga 11e 3rd Gen Version-
   LenovoThinkpad Yoga 11e 4th Gen Version-
   LenovoThinkpad Yoga 370 Version-
   LenovoBios Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.13% 0.286
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.