Lucene search

K
cve[email protected]CVE-2016-8224
HistoryNov 29, 2016 - 8:59 p.m.

CVE-2016-8224

2016-11-2920:59:02
CWE-310
web.nvd.nist.gov
17
lenovo
vulnerability
privilege escalation
circumvention
intel management engine
denial of service

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:N/I:N/A:C

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.8%

A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.

Affected configurations

NVD
Node
lenovobiosMatch-
OR
lenovonotebook_110_14ibr_biosMatch-
OR
lenovonotebook_110_15ibr_biosMatch-
OR
lenovonotebook_b70_80_biosMatch-
OR
lenovonotebook_e31_80_biosMatch-
OR
lenovonotebook_e40_80_biosMatch-
OR
lenovonotebook_e41_80_biosMatch-
OR
lenovonotebook_e51_80_biosMatch-
OR
lenovonotebook_g40_80_biosMatch-
OR
lenovonotebook_g50_80_biosMatch-
OR
lenovonotebook_g50_80_touch_biosMatch-
OR
lenovonotebook_ideapad_300_14ibr_biosMatch-
OR
lenovonotebook_ideapad_300_14isk_biosMatch-
OR
lenovonotebook_ideapad_300_15ibr_biosMatch-
OR
lenovonotebook_ideapad_300_15isk_biosMatch-
OR
lenovonotebook_ideapad_300_17isk_biosMatch-
OR
lenovonotebook_ideapad_510s_12isk_biosMatch-
OR
lenovonotebook_k21_80_biosMatch-
OR
lenovonotebook_k41_80_biosMatch-
OR
lenovonotebook_miix_710_12ikb_biosMatch-
OR
lenovonotebook_xiaoxin_air_12_biosMatch-
OR
lenovonotebook_yoga_510_14isk_biosMatch-
OR
lenovonotebook_yoga_510_15isk_biosMatch-
OR
lenovonotebook_yoga_710_11ikb_biosMatch-
OR
lenovonotebook_yoga_710_11isk_biosMatch-
OR
lenovonotebook_yoga_900_13isk_biosMatch-
OR
lenovonotebook_yoga_900s_12isk_biosMatch-
OR
lenovothinkserver_ts150_biosMatch-
OR
lenovothinkserver_ts450_biosMatch-
AND
lenovonotebook_110_14ibrMatch-
OR
lenovonotebook_110_15ibrMatch-
OR
lenovonotebook_b70_80Match-
OR
lenovonotebook_e31_80Match-
OR
lenovonotebook_e40_80Match-
OR
lenovonotebook_e41_80Match-
OR
lenovonotebook_e51_80Match-
OR
lenovonotebook_g40_80Match-
OR
lenovonotebook_g50_80Match-
OR
lenovonotebook_g50_80_touchMatch-
OR
lenovonotebook_ideapad_300_14ibrMatch-
OR
lenovonotebook_ideapad_300_14iskMatch-
OR
lenovonotebook_ideapad_300_15ibrMatch-
OR
lenovonotebook_ideapad_300_15iskMatch-
OR
lenovonotebook_ideapad_300_17iskMatch-
OR
lenovonotebook_ideapad_510s_12iskMatch-
OR
lenovonotebook_k21_80Match-
OR
lenovonotebook_k41_80Match-
OR
lenovonotebook_miix_710_12ikbMatch-
OR
lenovonotebook_xiaoxin_air_12Match-
OR
lenovonotebook_yoga_510_14iskMatch-
OR
lenovonotebook_yoga_510_15iskMatch-
OR
lenovonotebook_yoga_710_11ikbMatch-
OR
lenovonotebook_yoga_710_11iskMatch-
OR
lenovonotebook_yoga_900_13iskMatch-
OR
lenovonotebook_yoga_900s_12iskMatch-
OR
lenovothinkserver_ts150Match-
OR
lenovothinkserver_ts450Match-

CNA Affected

[
  {
    "product": "Lenovo Notebook models 110-14IBR/110-15IBR, B70-80, E31-80, E40-80, E41-80, E51-80, G40-80, G50-80, G50-80 Touch, Ideapad 300-14IBR/300-15IBR, Ideapad 300-14ISK/300-15ISK/300-17ISK, Ideapad 510S-12ISK, K21-80, K41-80, MIIX 710-12IKB , XiaoXin Air 12, YOGA 510-14ISK/510-15ISK, YOGA 710-11IKB, Yoga 710-11ISK, Yoga 900-13ISK, YOGA 900S-12ISK; ThinkServer models ThinkServer TS150, ThinkServer TS450",
    "vendor": "Lenovo Group Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "various"
      }
    ]
  }
]

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:N/I:N/A:C

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.8%

Related for CVE-2016-8224