ZeroHour

CVE-2021-3843

CVSS 3.1
6.7 medium
EPSS
<1%p20
Published
()
Modified
Description

A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Vendors
lenovo
Products
thinkpad 11e 3rd gen firmware, thinkpad 11e 4th gen i3 firmware, thinkpad 11e 4th gen i7 firmware, thinkpad 11e 4th gen i5 firmware, thinkpad 11e 4th gen celeron firmware, thinkpad 11e yoga gen 6 firmware, thinkpad 13 gen 2 firmware, thinkpad l13 firmware, thinkpad l13 gen 2 firmware, thinkpad l13 yoga firmware, thinkpad l13 yoga gen 2 firmware, thinkpad l14 gen 1 firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.