6.7

CVE-2021-3971

A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.

Data is provided by the National Vulnerability Database (NVD)
LenovoIdeapad 3-14ada05 Firmware Version < e8cn33ww
   LenovoIdeapad 3-14ada05 Version-
LenovoIdeapad 3-14ada6 Firmware Version < hbcn21ww
   LenovoIdeapad 3-14ada6 Version-
LenovoIdeapad 3-14alc6 Firmware Version < glcn43ww
   LenovoIdeapad 3-14alc6 Version-
LenovoIdeapad 3-14are05 Firmware Version < dzcn42ww
   LenovoIdeapad 3-14are05 Version-
LenovoIdeapad 3-15ada6 Firmware Version < hbcn21ww
   LenovoIdeapad 3-15ada6 Version-
LenovoIdeapad 3-15alc6 Firmware Version < glcn43ww
   LenovoIdeapad 3-15alc6 Version-
LenovoIdeapad 3-15are05 Firmware Version < dzcn42ww
   LenovoIdeapad 3-15are05 Version-
LenovoIdeapad 3-15igl05 Firmware Version < dvcn23ww
   LenovoIdeapad 3-15igl05 Version-
LenovoIdeapad 3-17ada05 Firmware Version < e8cn33ww
   LenovoIdeapad 3-17ada05 Version-
LenovoIdeapad 3-17ada6 Firmware Version < hbcn21ww
   LenovoIdeapad 3-17ada6 Version-
LenovoIdeapad 3-17alc6 Firmware Version < glcn43ww
   LenovoIdeapad 3-17alc6 Version-
LenovoIdeapad 3-17are05 Firmware Version < dzcn42ww
   LenovoIdeapad 3-17are05 Version-
LenovoIdeapad 3-17iil05 Firmware Version < emcn52ww
   LenovoIdeapad 3-17iil05 Version-
LenovoIdeapad 3-15ada05 Firmware Version < e8cn33ww
   LenovoIdeapad 3-15ada05 Version-
LenovoL3-15itl6 Firmware Version < gfcn23ww
   LenovoL3-15itl6 Version-
LenovoL340-15irh Firmware Version < bgcn35ww
   LenovoL340-15irh Version-
LenovoL340-15iwl Firmware Version < atcn46ww
   LenovoL340-15iwl Version-
LenovoL340-15iwl Touch Firmware Version < atcn46ww
   LenovoL340-15iwl Touch Version-
LenovoL340-17irh Firmware Version < bgcn35ww
   LenovoL340-17irh Version-
LenovoL340-17iwl Firmware Version < atcn46ww
   LenovoL340-17iwl Version-
LenovoLegion 5 Pro-16ach6 Firmware Version < hhcn25ww
   LenovoLegion 5 Pro-16ach6 Version-
LenovoLegion 5 Pro-16ach6h Firmware Version < gkcn51ww
   LenovoLegion 5 Pro-16ach6h Version-
LenovoLegion 5 Pro-16ith6 Firmware Version < h1cn46ww
   LenovoLegion 5 Pro-16ith6 Version-
LenovoLegion 5 Pro-16ith6h Firmware Version < h1cn46ww
   LenovoLegion 5 Pro-16ith6h Version-
LenovoLegion 5-15ach6 Firmware Version < hhcn25ww
   LenovoLegion 5-15ach6 Version-
LenovoLegion 5-15ach6a Firmware Version < g9cn28ww
   LenovoLegion 5-15ach6a Version-
LenovoLegion 5-15ach6h Firmware Version < gkcn51ww
   LenovoLegion 5-15ach6h Version-
LenovoLegion 5-15ith6 Firmware Version < h1cn46ww
   LenovoLegion 5-15ith6 Version-
LenovoLegion 5-15ith6h Firmware Version < h1cn46ww
   LenovoLegion 5-15ith6h Version-
LenovoLegion 5-17ach6 Firmware Version < hhcn25ww
   LenovoLegion 5-17ach6 Version-
LenovoLegion 5-17ach6h Firmware Version < gkcn51ww
   LenovoLegion 5-17ach6h Version-
LenovoLegion 5-17ith6 Firmware Version < h1cn46ww
   LenovoLegion 5-17ith6 Version-
LenovoLegion 5-17ith6h Firmware Version < h1cn46ww
   LenovoLegion 5-17ith6h Version-
LenovoLegion 7-16achg6 Firmware Version < gkcn51ww
   LenovoLegion 7-16achg6 Version-
LenovoLegion 7-16ithg6 Firmware Version < gkcn51ww
   LenovoLegion 7-16ithg6 Version-
LenovoLegion Y540-15irh Firmware Version < bhcn44ww
   LenovoLegion Y540-15irh Version-
LenovoLegion Y540-15irh-pg0 Firmware Version < bhcn44ww
   LenovoLegion Y540-15irh-pg0 Version-
LenovoLegion Y540-17irh Firmware Version < bhcn44ww
   LenovoLegion Y540-17irh Version-
LenovoLegion Y540-17irh-pg0 Firmware Version < bhcn44ww
   LenovoLegion Y540-17irh-pg0 Version-
LenovoLegion Y545 Firmware Version < bhcn44ww
   LenovoLegion Y545 Version-
LenovoLegion Y545-pg0 Firmware Version < bhcn44ww
   LenovoLegion Y545-pg0 Version-
LenovoLegion Y7000-2019 Firmware Version < bhcn44ww
   LenovoLegion Y7000-2019 Version-
LenovoLegion Y7000-2019-pg0 Firmware Version < bhcn44ww
   LenovoLegion Y7000-2019-pg0 Version-
LenovoS145-14api Firmware Version < bucn31ww
   LenovoS145-14api Version-
LenovoS145-14ast Firmware Version < aycn26ww
   LenovoS145-14ast Version-
LenovoS145-14igm Firmware Version < awcn28ww
   LenovoS145-14igm Version-
LenovoS145-14iil Firmware Version < dkcn54ww
   LenovoS145-14iil Version-
LenovoS145-15api Firmware Version < bucn31ww
   LenovoS145-15api Version-
LenovoS145-15ast Firmware Version < aycn26ww
   LenovoS145-15ast Version-
LenovoS145-15igm Firmware Version < awcn28ww
   LenovoS145-15igm Version-
LenovoS145-15iil Firmware Version < dkcn54ww
   LenovoS145-15iil Version-
LenovoS540-13api Firmware Version < cxcn34ww
   LenovoS540-13api Version-
LenovoV14 G2-acl Firmware Version < glcn43ww
   LenovoV14 G2-acl Version-
LenovoV14-ada Firmware Version < e8cn33ww
   LenovoV14-ada Version-
LenovoV14-are Firmware Version < dzcn42ww
   LenovoV14-are Version-
LenovoV14-igl Firmware Version < dvcn23ww
   LenovoV14-igl Version-
LenovoV14-iil Firmware Version < dkcn54ww
   LenovoV14-iil Version-
LenovoV140-15iwl Firmware Version < atcn46ww
   LenovoV140-15iwl Version-
LenovoV15 G2-alc Firmware Version < glcn43ww
   LenovoV15 G2-alc Version-
LenovoV15-ada Firmware Version < e8cn33ww
   LenovoV15-ada Version-
LenovoV15-igl Firmware Version < dvcn23ww
   LenovoV15-igl Version-
LenovoV15-iil Firmware Version < dkcn54ww
   LenovoV15-iil Version-
LenovoV17-iil Firmware Version < emcn52ww
   LenovoV17-iil Version-
LenovoV340-17iwl Firmware Version < atcn46ww
   LenovoV340-17iwl Version-
LenovoYoga Slim 7 Pro-14ach5 D Firmware Version < hecn24ww
   LenovoYoga Slim 7 Pro-14ach5 D Version-
LenovoIdeapad 3-14iil05 Firmware Version < dvcn23ww
   LenovoIdeapad 3-14iil05 Version-
LenovoIdeapad 3-14igl05 Firmware Version < emcn52ww
   LenovoIdeapad 3-14igl05 Version-
LenovoIdeapad 3-15iil05 Firmware Version < emcn52ww
   LenovoIdeapad 3-15iil05 Version-
LenovoIdeapad 5-15are05 Firmware Version < e7cn44ww
   LenovoIdeapad 5-15are05 Version-
LenovoIdeapad Gaming 3-15arh05 Firmware Version < fccn17ww
   LenovoIdeapad Gaming 3-15arh05 Version-
LenovoIdeapad Gaming 3-15imh05 Firmware Version < egcn36ww
   LenovoIdeapad Gaming 3-15imh05 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.13% 0.863
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-489 Active Debug Code

The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.