7.2
CVE-2021-3843
- EPSS 0.04%
- Published 12.11.2021 22:15:08
- Last modified 21.11.2024 06:22:37
- Source psirt@lenovo.com
- Teams watchlist Login
- Open Login
A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Data is provided by the National Vulnerability Database (NVD)
Lenovo ≫ Thinkpad 11e 3rd Gen Firmware SwEditionbraswell Version <= 1.22
Lenovo ≫ Thinkpad 11e 3rd Gen Firmware SwEditionskylate Version <= 1.29
Lenovo ≫ Thinkpad 11e 4th Gen I3 Firmware Version <= 1.22
Lenovo ≫ Thinkpad 11e 4th Gen I7 Firmware Version <= 1.22
Lenovo ≫ Thinkpad 11e 4th Gen I5 Firmware Version <= 1.22
Lenovo ≫ Thinkpad 11e 4th Gen Celeron Firmware Version <= 1.27
Lenovo ≫ Thinkpad 11e Yoga Gen 6 Firmware Version <= 1.12
Lenovo ≫ Thinkpad 13 Gen 2 Firmware Version <= 1.29
Lenovo ≫ Thinkpad L13 Firmware Version <= 1.31
Lenovo ≫ Thinkpad L13 Gen 2 Firmware SwEditionnon-vpro Version <= 1.11
Lenovo ≫ Thinkpad L13 Gen 2 Firmware SwEditionvpro Version <= 1.08
Lenovo ≫ Thinkpad L13 Yoga Firmware Version <= 1.31
Lenovo ≫ Thinkpad L13 Yoga Gen 2 Firmware SwEditionnon-vpro Version <= 1.11
Lenovo ≫ Thinkpad L13 Yoga Gen 2 Firmware SwEditionvpro Version <= 1.08
Lenovo ≫ Thinkpad L14 Gen 1 Firmware Version < 1.15
Lenovo ≫ Thinkpad L14 Firmware Version < 1.20.1.17
Lenovo ≫ Thinkpad L15 Gen 1 Firmware Version < 1.15
Lenovo ≫ Thinkpad L15 Firmware Version < 1.20.1.17
Lenovo ≫ Thinkpad L380 Firmware Version <= 1.26
Lenovo ≫ Thinkpad L380 Yoga Firmware Version <= 1.26
Lenovo ≫ Thinkpad L390 Yoga Firmware Version <= 1.35
Lenovo ≫ Thinkpad L390 Firmware Version <= 1.35
Lenovo ≫ Thinkpad S5 2nd Gen Firmware Version <= 1.28
Lenovo ≫ Thinkpad T460 Firmware Version <= 1.43.1.11
Lenovo ≫ Thinkpad S2 Gen 6 Firmware Version <= 2021-09-30
Lenovo ≫ Thinkpad S2 Yoga Gen 6 Firmware Version <= 2021-09-30
Lenovo ≫ Thinkpad X12 Detachable Gen 1 Firmware Version < 1.16
Lenovo ≫ Thinkpad X260 Firmware Version <= 1.47\/1.15
Lenovo ≫ Thinkpad X380 Yoga Firmware Version <= 1.34
Lenovo ≫ Thinkpad X390 Yoga Firmware Version < n2let87w
Lenovo ≫ Thinkpad 11e 5th Gen Firmware Version <= 1.13
Lenovo ≫ Thinkpad 11e 5th Gen Firmware Version <= 1.13
Lenovo ≫ Thinkpad X1 Fold Gen 1 Firmware Version < n2pet50w
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.078 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
psirt@lenovo.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.