ZeroHour

CVE-2018-9069

CVSS 3.1
5.9 medium
EPSS
<1%p43
Published
()
Modified
Description

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.

Vendors
hplenovo
Products
310s-14isk firmware, 320-15ikbra firmware, 320-15ikbrn firmware, 320-15ikbrn touch firmware, 320-17ikbrn, 320s-14ikb, 320s-15ikb firmware, 320s-15isk firmware, 510s-14isk firmware, 520-15ikbrn firmware, 520s-14ikb firmware, 710s plus-13ikb 16g firmware
Weakness
CWE-362
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.