6.9
CVE-2021-3519
- EPSS 0.03%
- Veröffentlicht 12.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:44
- Quelle psirt@lenovo.com
- CVE-Watchlists
- Unerledigt
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Ideacentre C5-14mb05 Firmware Version < o4hkt33a
Lenovo ≫ Ideacentre 3-07imb05 Firmware Version < m2vkt18a
Lenovo ≫ Ideacentre 5-14imb05 Firmware Version < o4hkt33a
Lenovo ≫ Ideacentre 5-14iob6 Firmware Version < m3gkt29a
Lenovo ≫ Ideacentre Creator 5-14iob6 Firmware Version < m3gkt29a
Lenovo ≫ Ideacentre G5-14imb05 Firmware Version < o4hkt33a
Lenovo ≫ Ideacentre Gaming 5-14iob6 Firmware Version < m3gkt29a
Lenovo ≫ Thinkcentre M60e Tiny Firmware Version < m3skt1ea
Lenovo ≫ Thinkcentre M630e Firmware Version < m28kt36a
Lenovo ≫ Thinkcentre M70a Firmware Version <= m2skt21a
Lenovo ≫ Thinkcentre M70s Firmware Version < m2tkt3ca
Lenovo ≫ Thinkcentre M70t Firmware Version < m2tkt3ca
Lenovo ≫ Thinkcentre M710e Firmware Version < m1zkt37a
Lenovo ≫ Thinkcentre M710s Firmware Version < m16kt67a
Lenovo ≫ Thinkcentre M710t Firmware Version < m16kt67a
Lenovo ≫ Thinkcentre M720e Firmware Version < m30kt23a
Lenovo ≫ Thinkcentre M75n Firmware Version < m33kt21a
Lenovo ≫ Thinkcentre M75s Gen 2 Firmware SwEditionmatisse Version < m3bkt24a
Lenovo ≫ Thinkcentre M70a Gen 2 Firmware Version < m3nkt17a
Lenovo ≫ Thinkcentre M70c Firmware Version < m2vkt18a
Lenovo ≫ Thinkcentre M70q Firmware Version < m2wkt49a
Lenovo ≫ Thinkcentre M75s Gen 2 Firmware SwEditionpicasso/renoir Version < m3akt35a
Lenovo ≫ Thinkcentre M75t Gen 2 Firmware SwEditionmatisse Version < m3bkt24a
Lenovo ≫ Thinkcentre M75t Gen 2 Firmware SwEditionpicasso/renoir Version < m3akt35a
Lenovo ≫ Thinkcentre M80q Firmware Version < m2wkt49a
Lenovo ≫ Thinkcentre M80s Firmware Version < m2tkt3ca
Lenovo ≫ Thinkcentre M80t Firmware Version < m2tkt3ca
Lenovo ≫ Thinkcentre M810z Firmware Version < m1ckt47a
Lenovo ≫ Thinkcentre M820z Firmware Version < m1nkt57a
Lenovo ≫ Thinkcentre M90a Firmware Version < m2rkt47a
Lenovo ≫ Thinkcentre M90q Tiny Firmware Version < m2wkt49a
Lenovo ≫ Thinkcentre M90s Firmware Version < m2tkt3ca
Lenovo ≫ Thinkcentre M90t Firmware Version < m2tkt3ca
Lenovo ≫ Thinkcentre Qt M410 Firmware Version < m16kt67a
Lenovo ≫ Thinkcentre Qt B415 Firmware Version < m16kt67a
Lenovo ≫ Thinkcentre Qt M415 Firmware Version < m16kt67a
Lenovo ≫ Thinkcentre E75 T/s Firmware Version < m16kt67a
Lenovo ≫ Ideacentre 310s-08igm Firmware Version <= m1tkt31a
Lenovo ≫ Ideacentre 510a-15arr Firmware Version <= o4dkt41a
Lenovo ≫ Ideacentre 510s-07icb Firmware Version < m22kt46a
Lenovo ≫ Ideacentre 510s-07ick Firmware Version < m30kt24a
Lenovo ≫ Ideacentre 510s-07ick Firmware Version < m30kt23a
Lenovo ≫ V30a-22iml Firmware Version < m37kt26a
Lenovo ≫ V330 Firmware Version <= m1tkt32a
Lenovo ≫ V50a-24imb Firmware Version < m36kt27a
Lenovo ≫ V50s-07imb Firmware Version < m2vkt18a
Lenovo ≫ V50a-22imb Firmware Version < m36kt27a
Lenovo ≫ V50t-13imb Firmware Version < o4hkt33a
Lenovo ≫ V50t-13imb G2 Firmware Version < m3gkt29a
Lenovo ≫ V520 Firmware Version < m16kt67a
Lenovo ≫ V520s Firmware Version < m16kt67a
Lenovo ≫ V530-15arr Firmware Version <= o4dkt41a
Lenovo ≫ V530-15icr Firmware Version < m2ykt29a
Lenovo ≫ V530s-07icb Firmware Version < m30kt23a
Lenovo ≫ V530s-07icr Firmware Version < m30kt23a
Lenovo ≫ V55t-15api Firmware Version <= o4dkt41a
Lenovo ≫ Thinkstation P340 Tiny Firmware Version < m2wkt49a
Lenovo ≫ Thinkstation P340 Firmware Version < s08kt3fa
Lenovo ≫ Thinkstation P520 Firmware Version <= s03kt49a
Lenovo ≫ Thinkstation P520c Firmware Version <= s03kt49a
Lenovo ≫ Thinkstation P720 Firmware Version < s04kt54a\/s04kt54p
Lenovo ≫ Thinkstation P920 Firmware Version < s04kt54a\/s04kt54p
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.064 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
| psirt@lenovo.com | 6.4 | 0.9 | 5.5 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.