Medium severity6.7NVD Advisory· Published Nov 11, 2020· Updated Jun 17, 2026
CVE-2020-8353
CVE-2020-8353
Description
Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.
Affected products
16- cpe:2.3:o:lenovo:thinkcentre_m80s_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkcentre_m80t_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkcentre_m90s_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkcentre_m90t_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkcentre_m910z_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkcentre_m920q_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkcentre_m920s_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkcentre_m920t_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkcentre_m920z_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkstation_p330_tiny_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkstation_p330s_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkstation_p330t_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkstation_p340s_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- cpe:2.3:o:lenovo:thinkstation_p340t_firmware:*:*:*:*:*:*:*:*Range: <2020-08-10
- Range: <=2020-08-10
- Range: unspecified
Patches
Vulnerability mechanics
References
1- support.lenovo.com/us/en/product_security/LEN-44725nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.