ZeroHour

CVE-2020-8335

CVSS 3.1
6.8 medium
EPSS
<1%p24
Published
()
Modified
Description

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access.

Vendors
lenovo
Products
thinkpad a275 firmware, thinkpad a285 firmware, thinkpad a475 firmware, thinkpad a485 firmware, thinkpad t495 drift firmware, thinkpad t495s jazz firmware, thinkpad x1 carbon \(20bx\) firmware, thinkpad x395 firmware
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.