6.8
CVE-2021-3453
- EPSS 0.05%
- Veröffentlicht 16.07.2021 21:15:10
- Zuletzt bearbeitet 21.11.2024 06:21:34
- Quelle psirt@lenovo.com
- Teams Watchlist Login
- Unerledigt Login
Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Thinkpad Helix Firmware Versionn17etb4w
Lenovo ≫ Thinkpad T550 Firmware Versionn11et53w
Lenovo ≫ Thinkpad W550s Firmware Versionn11et53w
Lenovo ≫ Thinkpad X1 Carbon 3rd Gen Firmware Versionn14et55w
Lenovo ≫ Thinkpad X250 Firmware Versionn10et62w
Lenovo ≫ Thinkpad Yoga 15 Firmware Versionn19et65w
Lenovo ≫ 730s-13iml Firmware Version-
Lenovo ≫ Ideapad 1-11igl05 Firmware Version-
Lenovo ≫ Ideapad 1-14igl05 Firmware Version-
Lenovo ≫ Ideapad S940-14iil Firmware Version-
Lenovo ≫ Ideapad S940-14iwl Firmware Version-
Lenovo ≫ Ideapad Slim 1-11ast-05 Firmware Version-
Lenovo ≫ Ideapad Slim 1-14ast-05 Firmware Version-
Lenovo ≫ V130-15igm Firmware Version-
Lenovo ≫ V330-15ikb Firmware Version-
Lenovo ≫ V330-15isk Firmware Version-
Lenovo ≫ Yoga S730-13iml Firmware Version-
Lenovo ≫ Yoga S940-14iil Firmware Version-
Lenovo ≫ Yoga S940-14iwl Firmware Version-
Lenovo ≫ Ideacentre Aio 5-24imb05 Firmware Version < 2021-09-30
Lenovo ≫ Ideacentre Aio 5-74imb05 Firmware Version < 2021-09-30
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.116 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.6 | 0.9 | 3.6 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:P/A:N
|
psirt@lenovo.com | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-693 Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.