BIOS
by Lenovo
CVEs (35)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-8354 | Med | 0.42 | 6.4 | 0.00 | Nov 11, 2020 | A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution. | ||
| CVE-2020-8333 | Med | 0.42 | 6.4 | 0.00 | Sep 24, 2020 | A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution | ||
| CVE-2020-8336 | Med | 0.42 | 6.4 | 0.00 | Jun 9, 2020 | Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash. | ||
| CVE-2020-8323 | Med | 0.42 | 6.4 | 0.00 | Jun 9, 2020 | A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. | ||
| CVE-2020-8322 | Med | 0.42 | 6.4 | 0.00 | Jun 9, 2020 | A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. | ||
| CVE-2020-8321 | Med | 0.42 | 6.4 | 0.00 | Jun 9, 2020 | A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. | ||
| CVE-2020-8320 | Med | 0.42 | 6.4 | 0.00 | Jun 9, 2020 | An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. | ||
| CVE-2020-8334 | Med | 0.40 | 6.1 | 0.00 | Jun 9, 2020 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access. | ||
| CVE-2019-6190 | Med | 0.33 | 5.0 | 0.00 | Feb 14, 2020 | Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled. | ||
| CVE-2022-40136 | Med | 0.29 | 4.4 | 0.00 | Jan 30, 2023 | An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | ||
| CVE-2022-40135 | Med | 0.29 | 4.4 | 0.00 | Jan 30, 2023 | An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | ||
| CVE-2022-40134 | Med | 0.29 | 4.4 | 0.00 | Jan 30, 2023 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | ||
| CVE-2016-8224 | Med | 0.29 | 4.4 | 0.00 | Nov 29, 2016 | A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or… | ||
| CVE-2019-6156 | Low | 0.21 | 3.3 | 0.00 | Apr 10, 2019 | In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in… | ||
| CVE-2020-8352 | Low | 0.16 | 2.4 | 0.00 | Nov 11, 2020 | In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes. |
- risk 0.42cvss 6.4epss 0.00
A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution.
- risk 0.42cvss 6.4epss 0.00
A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
- risk 0.42cvss 6.4epss 0.00
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.
- risk 0.42cvss 6.4epss 0.00
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
- risk 0.42cvss 6.4epss 0.00
A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
- risk 0.42cvss 6.4epss 0.00
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
- risk 0.42cvss 6.4epss 0.00
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
- risk 0.40cvss 6.1epss 0.00
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access.
- risk 0.33cvss 5.0epss 0.00
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.
- risk 0.29cvss 4.4epss 0.00
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
- risk 0.29cvss 4.4epss 0.00
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
- risk 0.29cvss 4.4epss 0.00
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
- risk 0.29cvss 4.4epss 0.00
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or…
- risk 0.21cvss 3.3epss 0.00
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in…
- risk 0.16cvss 2.4epss 0.00
In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.
Page 2 of 2