ZeroHour

CVE-2021-3453

CVSS 3.1
4.6 medium
EPSS
<1%p15
Published
()
Modified
Description

Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

Vendors
lenovo
Products
thinkpad helix firmware, thinkpad t550 firmware, thinkpad w550s firmware, thinkpad x1 carbon 3rd gen firmware, thinkpad x250 firmware, thinkpad yoga 15 firmware, 730s-13iml firmware, ideapad 1-11igl05 firmware, ideapad 1-14igl05 firmware, ideapad s940-14iil firmware, ideapad s940-14iwl firmware, ideapad slim 1-11ast-05 firmware
Weakness
CWE-693
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.