VYPR

Thinkpad S1 Firmware

by Lenovo

CVEs (3)

  • CVE-2018-9062MedJul 19, 2018
    risk 0.44cvss 6.8epss 0.01

    In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

  • CVE-2020-8323MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.

  • CVE-2020-8320MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.