CVE-2021-3519
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD
Description
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
Affected (62)
Products: Lenovo: Ideacentre C5 14mb05 Firmware, Ideacentre 3 07imb05 Firmware, Ideacentre 5 14imb05 Firmware, Ideacentre 5 14iob6 Firmware, Ideacentre Creator 5 14iob6 Firmware, Ideacentre G5 14imb05 Firmware, Ideacentre Gaming 5 14iob6 Firmware, Thinkcentre M60e Tiny Firmware, Thinkcentre M630e Firmware, Thinkcentre M70a Firmware, Thinkcentre M70s Firmware, Thinkcentre M70t Firmware, Thinkcentre M710e Firmware, Thinkcentre M710s Firmware, Thinkcentre M710t Firmware, Thinkcentre M720e Firmware, Thinkcentre M75n Firmware, Thinkcentre M75s Gen 2 Firmware, Thinkcentre M70a Gen 2 Firmware, Thinkcentre M70c Firmware, Thinkcentre M70q Firmware, Thinkcentre M75t Gen 2 Firmware, Thinkcentre M80q Firmware, Thinkcentre M80s Firmware, Thinkcentre M80t Firmware, Thinkcentre M810z Firmware, Thinkcentre M820z Firmware, Thinkcentre M90a Firmware, Thinkcentre M90q Tiny Firmware, Thinkcentre M90s Firmware, Thinkcentre M90t Firmware, Thinkcentre Qt M410 Firmware, Thinkcentre Qt B415 Firmware, Thinkcentre Qt M415 Firmware, Thinkcentre E75 T/s Firmware, Ideacentre 310s 08igm Firmware, Ideacentre 510a 15arr Firmware, Ideacentre 510s 07icb Firmware, Ideacentre 510s 07ick Firmware, V30a 22iml Firmware, V330 Firmware, V50a 24imb Firmware, V50s 07imb Firmware, V50a 22imb Firmware, V50t 13imb Firmware, V50t 13imb G2 Firmware, V520 Firmware, V520s Firmware, V530 15arr Firmware, V530 15icr Firmware, V530s 07icb Firmware, V530s 07icr Firmware, V55t 15api Firmware, Thinkstation P340 Tiny Firmware, Thinkstation P340 Firmware, Thinkstation P520 Firmware, Thinkstation P520c Firmware, Thinkstation P720 Firmware, Thinkstation P920 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before o4hkt33a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre C5 14mb05 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2vkt18a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre 3 07imb05 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before o4hkt33a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre 5 14imb05 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3gkt29a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre 5 14iob6 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3gkt29a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre Creator 5 14iob6 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before o4hkt33a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre G5 14imb05 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3gkt29a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre Gaming 5 14iob6 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3skt1ea |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M60e Tiny | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before m28kt36a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M630e | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to m2skt21a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M70a | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2tkt3ca |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M70s | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2tkt3ca |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M70t | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1zkt37a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M710e | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before m16kt67a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M710s | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before m16kt67a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M710t | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before m30kt23a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M720e | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before m33kt21a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M75n | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3bkt24a |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3nkt17a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M70a Gen 2 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2vkt18a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M70c | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2wkt49a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M70q | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3akt35a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M75s Gen 2 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3bkt24a |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3akt35a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M75t Gen 2 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2wkt49a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M80q | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2tkt3ca |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M80s | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2tkt3ca |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M80t | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1ckt47a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M810z | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1nkt57a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M820z | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2rkt47a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M90a | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2wkt49a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M90a Tiny | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2tkt3ca |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M90s | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2tkt3ca |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M90t | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before m16kt67a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre Qt M410 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before m16kt67a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre Qt B415 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before m16kt67a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre Qt M415 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before m16kt67a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre E75 T/s | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to m1tkt31a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre 310s 08igm | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to o4dkt41a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre 510a 15arr | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before m22kt46a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre 510s 07icb | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before m30kt24a |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before m30kt23a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideacentre 510s 07ick | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before m37kt26a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V30a 22iml | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to m1tkt32a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V330 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before m36kt27a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V50a 24imb | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2vkt18a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V50s 07imb | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before m36kt27a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V50a 22imb | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before o4hkt33a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V50t 13imb | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before m3gkt29a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V50t 13imb G2 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before m16kt67a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V520 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before m16kt67a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V520s | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Up to o4dkt41a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V530 15arr | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2ykt29a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V530 15icr | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before m30kt23a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V530s 07icb | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before m30kt23a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V530s 07icr | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to o4dkt41a |
| Running on/with | Platform Versions |
|---|---|
Lenovo V55t 15api | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before m2wkt49a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P340 Tiny | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before s08kt3fa |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P340 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to s03kt49a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P520 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to s03kt49a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P520c | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before s04kt54a\/s04kt54p |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P720 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before s04kt54a\/s04kt54p |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P920 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.