6.9

CVE-2021-3519

A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LenovoIdeacentre C5-14mb05 Firmware Version < o4hkt33a
   LenovoIdeacentre C5-14mb05 Version-
LenovoIdeacentre 3-07imb05 Firmware Version < m2vkt18a
   LenovoIdeacentre 3-07imb05 Version-
LenovoIdeacentre 5-14imb05 Firmware Version < o4hkt33a
   LenovoIdeacentre 5-14imb05 Version-
LenovoIdeacentre 5-14iob6 Firmware Version < m3gkt29a
   LenovoIdeacentre 5-14iob6 Version-
LenovoIdeacentre G5-14imb05 Firmware Version < o4hkt33a
   LenovoIdeacentre G5-14imb05 Version-
LenovoThinkcentre M60e Tiny Firmware Version < m3skt1ea
   LenovoThinkcentre M60e Tiny Version-
LenovoThinkcentre M630e Firmware Version < m28kt36a
   LenovoThinkcentre M630e Version-
LenovoThinkcentre M70a Firmware Version <= m2skt21a
   LenovoThinkcentre M70a Version-
LenovoThinkcentre M70s Firmware Version < m2tkt3ca
   LenovoThinkcentre M70s Version-
LenovoThinkcentre M70t Firmware Version < m2tkt3ca
   LenovoThinkcentre M70t Version-
LenovoThinkcentre M710e Firmware Version < m1zkt37a
   LenovoThinkcentre M710e Version-
LenovoThinkcentre M710s Firmware Version < m16kt67a
   LenovoThinkcentre M710s Version-
LenovoThinkcentre M710t Firmware Version < m16kt67a
   LenovoThinkcentre M710t Version-
LenovoThinkcentre M720e Firmware Version < m30kt23a
   LenovoThinkcentre M720e Version-
LenovoThinkcentre M75n Firmware Version < m33kt21a
   LenovoThinkcentre M75n Version-
LenovoThinkcentre M75s Gen 2 Firmware SwEditionmatisse Version < m3bkt24a
   LenovoThinkcentre M75s Gen 2 Version-
LenovoThinkcentre M70a Gen 2 Firmware Version < m3nkt17a
   LenovoThinkcentre M70a Gen 2 Version-
LenovoThinkcentre M70c Firmware Version < m2vkt18a
   LenovoThinkcentre M70c Version-
LenovoThinkcentre M70q Firmware Version < m2wkt49a
   LenovoThinkcentre M70q Version-
LenovoThinkcentre M75s Gen 2 Firmware SwEditionpicasso/renoir Version < m3akt35a
   LenovoThinkcentre M75s Gen 2 Version-
LenovoThinkcentre M75t Gen 2 Firmware SwEditionmatisse Version < m3bkt24a
   LenovoThinkcentre M75t Gen 2 Version-
LenovoThinkcentre M75t Gen 2 Firmware SwEditionpicasso/renoir Version < m3akt35a
   LenovoThinkcentre M75t Gen 2 Version-
LenovoThinkcentre M80q Firmware Version < m2wkt49a
   LenovoThinkcentre M80q Version-
LenovoThinkcentre M80s Firmware Version < m2tkt3ca
   LenovoThinkcentre M80s Version-
LenovoThinkcentre M80t Firmware Version < m2tkt3ca
   LenovoThinkcentre M80t Version-
LenovoThinkcentre M810z Firmware Version < m1ckt47a
   LenovoThinkcentre M810z Version-
LenovoThinkcentre M820z Firmware Version < m1nkt57a
   LenovoThinkcentre M820z Version-
LenovoThinkcentre M90a Firmware Version < m2rkt47a
   LenovoThinkcentre M90a Version-
LenovoThinkcentre M90q Tiny Firmware Version < m2wkt49a
   LenovoThinkcentre M90a Tiny Version-
LenovoThinkcentre M90s Firmware Version < m2tkt3ca
   LenovoThinkcentre M90s Version-
LenovoThinkcentre M90t Firmware Version < m2tkt3ca
   LenovoThinkcentre M90t Version-
LenovoThinkcentre Qt M410 Firmware Version < m16kt67a
   LenovoThinkcentre Qt M410 Version-
LenovoThinkcentre Qt B415 Firmware Version < m16kt67a
   LenovoThinkcentre Qt B415 Version-
LenovoThinkcentre Qt M415 Firmware Version < m16kt67a
   LenovoThinkcentre Qt M415 Version-
LenovoThinkcentre E75 T/s Firmware Version < m16kt67a
   LenovoThinkcentre E75 T/s Version-
LenovoIdeacentre 310s-08igm Firmware Version <= m1tkt31a
   LenovoIdeacentre 310s-08igm Version-
   MicrosoftWindows 10 Version- HwPlatformx64
LenovoIdeacentre 510a-15arr Firmware Version <= o4dkt41a
   LenovoIdeacentre 510a-15arr Version-
   MicrosoftWindows 10 Version- HwPlatformx64
LenovoIdeacentre 510s-07icb Firmware Version < m22kt46a
   LenovoIdeacentre 510s-07icb Version-
   MicrosoftWindows 10 Version- HwPlatformx64
LenovoIdeacentre 510s-07ick Firmware Version < m30kt24a
   LenovoIdeacentre 510s-07ick Version-
   MicrosoftWindows 10 Version- HwPlatformx64
LenovoIdeacentre 510s-07ick Firmware Version < m30kt23a
   LenovoIdeacentre 510s-07ick Version-
LenovoV30a-22iml Firmware Version < m37kt26a
   LenovoV30a-22iml Version-
LenovoV330 Firmware Version <= m1tkt32a
   LenovoV330 Version-
LenovoV50a-24imb Firmware Version < m36kt27a
   LenovoV50a-24imb Version-
LenovoV50s-07imb Firmware Version < m2vkt18a
   LenovoV50s-07imb Version-
LenovoV50a-22imb Firmware Version < m36kt27a
   LenovoV50a-22imb Version-
LenovoV50t-13imb Firmware Version < o4hkt33a
   LenovoV50t-13imb Version-
LenovoV50t-13imb G2 Firmware Version < m3gkt29a
   LenovoV50t-13imb G2 Version-
LenovoV520 Firmware Version < m16kt67a
   LenovoV520 Version-
LenovoV520s Firmware Version < m16kt67a
   LenovoV520s Version-
LenovoV530-15arr Firmware Version <= o4dkt41a
   LenovoV530-15arr Version-
LenovoV530-15icr Firmware Version < m2ykt29a
   LenovoV530-15icr Version-
LenovoV530s-07icb Firmware Version < m30kt23a
   LenovoV530s-07icb Version-
LenovoV530s-07icr Firmware Version < m30kt23a
   LenovoV530s-07icr Version-
LenovoV55t-15api Firmware Version <= o4dkt41a
   LenovoV55t-15api Version-
LenovoThinkstation P340 Tiny Firmware Version < m2wkt49a
   LenovoThinkstation P340 Tiny Version-
LenovoThinkstation P340 Firmware Version < s08kt3fa
   LenovoThinkstation P340 Version-
LenovoThinkstation P520 Firmware Version <= s03kt49a
   LenovoThinkstation P520 Version-
LenovoThinkstation P520c Firmware Version <= s03kt49a
   LenovoThinkstation P520c Version-
LenovoThinkstation P720 Firmware Version < s04kt54a\/s04kt54p
   LenovoThinkstation P720 Version-
LenovoThinkstation P920 Firmware Version < s04kt54a\/s04kt54p
   LenovoThinkstation P920 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.064
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
psirt@lenovo.com 6.4 0.9 5.5
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.