VYPR

BIOS

by Lenovo

CVEs (35)

  • CVE-2020-8354MedNov 11, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution.

  • CVE-2020-8333MedSep 24, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution

  • CVE-2020-8336MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.

  • CVE-2020-8323MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.

  • CVE-2020-8322MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.

  • CVE-2020-8321MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.

  • CVE-2020-8320MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

  • CVE-2020-8334MedJun 9, 2020
    risk 0.40cvss 6.1epss 0.00

    The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access.

  • CVE-2019-6190MedFeb 14, 2020
    risk 0.33cvss 5.0epss 0.00

    Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.

  • CVE-2022-40136MedJan 30, 2023
    risk 0.29cvss 4.4epss 0.00

    An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

  • CVE-2022-40135MedJan 30, 2023
    risk 0.29cvss 4.4epss 0.00

    An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

  • CVE-2022-40134MedJan 30, 2023
    risk 0.29cvss 4.4epss 0.00

    An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

  • CVE-2016-8224MedNov 29, 2016
    risk 0.29cvss 4.4epss 0.00

    A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or…

  • CVE-2019-6156LowApr 10, 2019
    risk 0.21cvss 3.3epss 0.00

    In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in…

  • CVE-2020-8352LowNov 11, 2020
    risk 0.16cvss 2.4epss 0.00

    In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.

Page 2 of 2