7.2

CVE-2021-4212

A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Data is provided by the National Vulnerability Database (NVD)
LenovoC340-14iml Firmware Version-
   LenovoC340-14iml Version-
LenovoC340-15iml Firmware Version-
   LenovoC340-15iml Version-
LenovoD330-10igm Firmware Version-
   LenovoD330-10igm Version-
LenovoDuet 3-10igl5 Firmware Version-
   LenovoDuet 3-10igl5 Version-
LenovoE41-50 Firmware Version-
   LenovoE41-50 Version-
LenovoFlex-14iml Firmware Version-
   LenovoFlex-14iml Version-
LenovoFlex-15iml Firmware Version-
   LenovoFlex-15iml Version-
LenovoIdeapad 3-14are05 Firmware Version-
   LenovoIdeapad 3-14are05 Version-
LenovoIdeapad 3-15are05 Firmware Version-
   LenovoIdeapad 3-15are05 Version-
LenovoIdeapad 3-17are05 Firmware Version-
   LenovoIdeapad 3-17are05 Version-
LenovoIdeapad 5-14alc05 Firmware Version-
   LenovoIdeapad 5-14alc05 Version-
LenovoIdeapad 5-14are05 Firmware Version-
   LenovoIdeapad 5-14are05 Version-
LenovoIdeapad 5-15itl05 Firmware Version-
   LenovoIdeapad 5-15itl05 Version-
LenovoL340-15irh Firmware Version-
   LenovoL340-15irh Version-
LenovoL340-15iwl Firmware Version-
   LenovoL340-15iwl Version-
LenovoL340-15iwl Touch Firmware Version-
   LenovoL340-15iwl Touch Version-
LenovoL340-17irh Firmware Version-
   LenovoL340-17irh Version-
LenovoL340-17iwl Firmware Version-
   LenovoL340-17iwl Version-
LenovoLegion Y540-15irh Firmware Version-
   LenovoLegion Y540-15irh Version-
LenovoLegion Y540-17irh Firmware Version-
   LenovoLegion Y540-17irh Version-
LenovoLegion Y545 Firmware Version-
   LenovoLegion Y545 Version-
LenovoLegion Y545-pg0 Firmware Version-
   LenovoLegion Y545-pg0 Version-
LenovoLegion Y7000-2019 Firmware Version-
   LenovoLegion Y7000-2019 Version-
LenovoS340-13iml Firmware Version-
   LenovoS340-13iml Version-
LenovoS340-14api Firmware Version-
   LenovoS340-14api Version-
LenovoS340-14iml Firmware Version-
   LenovoS340-14iml Version-
LenovoS340-15api Firmware Version-
   LenovoS340-15api Version-
LenovoS340-15api Touch Firmware Version-
   LenovoS340-15api Touch Version-
LenovoS340-15iml Firmware Version-
   LenovoS340-15iml Version-
LenovoS540-14iml Firmware Version-
   LenovoS540-14iml Version-
LenovoS540-14iml Touch Firmware Version-
   LenovoS540-14iml Touch Version-
LenovoS540-15iml Firmware Version-
   LenovoS540-15iml Version-
LenovoSlim 7-14are05 Firmware Version-
   LenovoSlim 7-14are05 Version-
LenovoSlim 7-14itl05 Firmware Version-
   LenovoSlim 7-14itl05 Version-
LenovoSlim 7-15iil05 Firmware Version-
   LenovoSlim 7-15iil05 Version-
LenovoSlim 7-15imh05 Firmware Version-
   LenovoSlim 7-15imh05 Version-
LenovoSlim 7-15itl05 Firmware Version-
   LenovoSlim 7-15itl05 Version-
LenovoThinkbook 13x Itg Firmware Version-
   LenovoThinkbook 13x Itg Version-
LenovoV14-are Firmware Version-
   LenovoV14-are Version-
LenovoV140-15iwl Firmware Version-
   LenovoV140-15iwl Version-
LenovoV340-17iwl Firmware Version-
   LenovoV340-17iwl Version-
LenovoYoga 6-13alc6 Firmware Version-
   LenovoYoga 6-13alc6 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.3
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.