ZeroHour

CVE-2019-6171

CVSS 3.1
6.8 medium
EPSS
<1%p28
Published
()
Modified
Description

A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.

Vendors
lenovo
Products
20f1 firmware, 20f2 firmware, 20jq firmware, 20jr firmware, 20g9 firmware, 20gb firmware, 20g8 firmware, 20ga firmware, 20ht firmware, 20hv firmware, 20hs firmware, 20hu firmware
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.