6.8

CVE-2021-3453

Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

Data is provided by the National Vulnerability Database (NVD)
LenovoThinkpad Helix Firmware Versionn17etb4w
   LenovoThinkpad Helix Version-
LenovoThinkpad T550 Firmware Versionn11et53w
   LenovoThinkpad T550 Version-
LenovoThinkpad W550s Firmware Versionn11et53w
   LenovoThinkpad W550s Version-
LenovoThinkpad X250 Firmware Versionn10et62w
   LenovoThinkpad X250 Version-
LenovoThinkpad Yoga 15 Firmware Versionn19et65w
   LenovoThinkpad Yoga 15 Version-
Lenovo730s-13iml Firmware Version-
   Lenovo730s-13iml Version-
LenovoIdeapad 1-11igl05 Firmware Version-
   LenovoIdeapad 1-11igl05 Version-
LenovoIdeapad 1-14igl05 Firmware Version-
   LenovoIdeapad 1-14igl05 Version-
LenovoV130-15igm Firmware Version-
   LenovoV130-15igm Version-
LenovoV330-15ikb Firmware Version-
   LenovoV330-15ikb Version-
LenovoV330-15isk Firmware Version-
   LenovoV330-15isk Version-
LenovoYoga S730-13iml Firmware Version-
   LenovoYoga S730-13iml Version-
LenovoYoga S940-14iil Firmware Version-
   LenovoYoga S940-14iil Version-
LenovoYoga S940-14iwl Firmware Version-
   LenovoYoga S940-14iwl Version-
LenovoIdeacentre Aio 5-24imb05 Firmware Version < 2021-09-30
   LenovoIdeacentre Aio 5-24imb05 Version-
LenovoIdeacentre Aio 5-74imb05 Firmware Version < 2021-09-30
   LenovoIdeacentre Aio 5-74imb05 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.116
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.6 0.9 3.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
psirt@lenovo.com 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.