CVE-2021-3719
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Affected (20)
Products: Lenovo: Thinkcentre E93 Firmware, Thinkcentre M600 Firmware, Thinkcentre M700 Tiny Firmware, Thinkcentre M73 Firmware, Thinkcentre M73p Firmware, Thinkcentre M800 Firmware, Thinkcentre M818z Firmware, Thinkcentre M83 Firmware, Thinkcentre M900 Firmware, Thinkcentre M900x Firmware, Thinkcentre M93 Firmware, Thinkcentre M93p Firmware, Thinkcentre M4500q Firmware, Thinkcentre M6500t/s Firmware, Thinkcentre M8500t/s Firmware, Thinkcentre X1 Firmware, Thinkstation P300 Firmware, Thinkstation P500 Firmware, Thinkstation P700 Firmware, Thinkstation P900 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before fbktdfa |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre E93 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before m00kt65a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M600 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before fwktb9a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M700 Tiny | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before fhkt86a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M73 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before fbktdfa |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M73p | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before fwktb9a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M800 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before m1ekt23a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M818z | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before fbktdfa |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M83 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before fwktb9a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M900 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before fwktb9a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M900x | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before fbktdfa |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M93 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before fbktdfa |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M93p | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before fhkt86a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M4500q | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before fbktdfa |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M6500t/s | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before fbktdfa |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M8500t/s | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before m0hkt50a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre X1 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before fbktdfa |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P300 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before a4ktaba |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P500 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before a5ktaba |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P700 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before a6ktaba |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P900 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.