ZeroHour

CVE-2021-3786

CVSS 3.1
5.5 medium
EPSS
<1%p14
Published
()
Modified
Description

A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.

Vendors
lenovo
Products
thinkpad x380 yoga firmware, thinkpad x1 fold gen 1 firmware, thinkpad yoga 260 firmware, thinkpad yoga 11e 3rd gen firmware, thinkpad yoga 15 firmware, thinkpad yoga 370 firmware, thinkpad x12 detachable gen 1 firmware, thinkpad x390 firmware, thinkpad yoga 11e 4th gen firmware, thinkpad yoga 11e 5th gen firmware, thinkpad x250 firmware, thinkpad x260 firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.