VYPR

Notebook BIOS

by Lenovo

CVEs (3)

  • CVE-2021-3972MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.03

    A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

  • CVE-2017-3754MedJul 17, 2017
    risk 0.44cvss 6.7epss 0.00

    Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.

  • CVE-2020-8323MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.