Lucene search

K
cve[email protected]CVE-2021-3843
HistoryNov 12, 2021 - 10:15 p.m.

CVE-2021-3843

2021-11-1222:15:08
CWE-20
web.nvd.nist.gov
19
vulnerability
smi
eeprom
thinkpad
cve-2021-3843
nvd
code execution

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Affected configurations

NVD
Node
lenovothinkpad_11e_3rd_gen_firmwareRange1.22braswell
AND
lenovothinkpad_11e_3rd_genMatch-
Node
lenovothinkpad_11e_3rd_gen_firmwareRange1.29skylate
AND
lenovothinkpad_11e_3rd_genMatch-
Node
lenovothinkpad_11e_4th_gen_i3_firmwareRange1.22
AND
lenovothinkpad_11e_4th_gen_i3Match-
Node
lenovothinkpad_11e_4th_gen_i7_firmwareRange1.22
AND
lenovothinkpad_11e_4th_gen_i7Match-
Node
lenovothinkpad_11e_4th_gen_i5_firmwareRange1.22
AND
lenovothinkpad_11e_4th_gen_i5Match-
Node
lenovothinkpad_11e_4th_gen_celeron_firmwareRange1.27
AND
lenovothinkpad_11e_4th_gen_celeronMatch-
Node
lenovothinkpad_11e_yoga_gen_6_firmwareRange1.12
AND
lenovothinkpad_11e_yoga_gen_6Match-
Node
lenovothinkpad_13_gen_2_firmwareRange1.29
AND
lenovothinkpad_13_gen_2Match-
Node
lenovothinkpad_l13_firmwareRange1.31
AND
lenovothinkpad_l13Match-
Node
lenovothinkpad_l13_gen_2_firmwareRange1.11non-vpro
AND
lenovothinkpad_l13_gen_2Match-
Node
lenovothinkpad_l13_gen_2_firmwareRange1.08vpro
AND
lenovothinkpad_l13_gen_2Match-
Node
lenovothinkpad_l13_yoga_firmwareRange1.31
AND
lenovothinkpad_l13_yogaMatch-
Node
lenovothinkpad_l13_yoga_gen_2_firmwareRange1.11non-vpro
AND
lenovothinkpad_l13_yoga_gen_2Match-
Node
lenovothinkpad_l13_yoga_gen_2_firmwareRange1.08vpro
AND
lenovothinkpad_l13_yoga_gen_2Match-
Node
lenovothinkpad_l14_gen_1_firmwareRange<1.15
AND
lenovothinkpad_l14_gen_1Match-
Node
lenovothinkpad_l14_firmwareRange<1.20.1.17
AND
lenovothinkpad_l14Match-
Node
lenovothinkpad_l15_gen_1_firmwareRange<1.15
AND
lenovothinkpad_l15_gen_1Match-
Node
lenovothinkpad_l15_firmwareRange<1.20.1.17
AND
lenovothinkpad_l15Match-
Node
lenovothinkpad_l380_firmwareRange1.26
AND
lenovothinkpad_l380Match-
Node
lenovothinkpad_l380_yoga_firmwareRange1.26
AND
lenovothinkpad_l380_yogaMatch-
Node
lenovothinkpad_l390_yoga_firmwareRange1.35
AND
lenovothinkpad_l390_yogaMatch-
Node
lenovothinkpad_l390_firmwareRange1.35
AND
lenovothinkpad_l390Match-
Node
lenovothinkpad_s5_2nd_gen_firmwareRange1.28
AND
lenovothinkpad_s5_2nd_genMatch-
Node
lenovothinkpad_t460_firmwareRange1.43.1.11
AND
lenovothinkpad_t460Match-
Node
lenovothinkpad_s2_gen_6_firmwareRange2021-09-30
AND
lenovothinkpad_s2_gen_6Match-
Node
lenovothinkpad_s2_yoga_gen_6_firmwareRange2021-09-30
AND
lenovothinkpad_s2_yoga_gen_6Match-
Node
lenovothinkpad_x12_detachable_gen_1_firmwareRange<1.16
AND
lenovothinkpad_x12_detachable_gen_1Match-
Node
lenovothinkpad_x260_firmwareRange1.47\/1.15
AND
lenovothinkpad_x260Match-
Node
lenovothinkpad_x380_yoga_firmwareRange1.34
AND
lenovothinkpad_x380_yogaMatch-
Node
lenovothinkpad_x390_yoga_firmwareRange<n2let87w
AND
lenovothinkpad_x390_yogaMatch-
Node
lenovothinkpad_11e_5th_gen_firmwareRange1.13
AND
lenovothinkpad_11e_5th_genMatch-
Node
lenovothinkpad_11e_5th_gen_firmwareRange1.13
AND
lenovothinkpad_yoga_370Match-
Node
lenovothinkpad_x1_fold_gen_1_firmwareRange<n2pet50w
AND
lenovothinkpad_x1_fold_gen_1Match-

CNA Affected

[
  {
    "product": "ThinkPad BIOS",
    "vendor": "Lenovo",
    "versions": [
      {
        "status": "affected",
        "version": "various"
      }
    ]
  }
]

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2021-3843