CVE-2021-3971
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.
Affected (73)
Products: Lenovo: Ideapad 3 14ada05 Firmware, Ideapad 3 14ada6 Firmware, Ideapad 3 14alc6 Firmware, Ideapad 3 14are05 Firmware, Ideapad 3 15ada6 Firmware, Ideapad 3 15alc6 Firmware, Ideapad 3 15are05 Firmware, Ideapad 3 15igl05 Firmware, Ideapad 3 17ada05 Firmware, Ideapad 3 17ada6 Firmware, Ideapad 3 17alc6 Firmware, Ideapad 3 17are05 Firmware, Ideapad 3 17iil05 Firmware, Ideapad 3 15ada05 Firmware, L3 15itl6 Firmware, L340 15irh Firmware, L340 15iwl Firmware, L340 15iwl Touch Firmware, L340 17irh Firmware, L340 17iwl Firmware, Legion 5 Pro 16ach6 Firmware, Legion 5 Pro 16ach6h Firmware, Legion 5 Pro 16ith6 Firmware, Legion 5 Pro 16ith6h Firmware, Legion 5 15ach6 Firmware, Legion 5 15ach6a Firmware, Legion 5 15ach6h Firmware, Legion 5 15ith6 Firmware, Legion 5 15ith6h Firmware, Legion 5 17ach6 Firmware, Legion 5 17ach6h Firmware, Legion 5 17ith6 Firmware, Legion 5 17ith6h Firmware, Legion 7 16achg6 Firmware, Legion 7 16ithg6 Firmware, Legion Y540 15irh Firmware, Legion Y540 15irh Pg0 Firmware, Legion Y540 17irh Firmware, Legion Y540 17irh Pg0 Firmware, Legion Y545 Firmware, Legion Y545 Pg0 Firmware, Legion Y7000 2019 Firmware, Legion Y7000 2019 Pg0 Firmware, S145 14api Firmware, S145 14ast Firmware, S145 14igm Firmware, S145 14iil Firmware, S145 15api Firmware, S145 15ast Firmware, S145 15igm Firmware, S145 15iil Firmware, S540 13api Firmware, V14 G2 Acl Firmware, V14 Ada Firmware, V14 Are Firmware, V14 Igl Firmware, V14 Iil Firmware, V140 15iwl Firmware, V15 G2 Alc Firmware, V15 Ada Firmware, V15 Igl Firmware, V15 Iil Firmware, V17 Iil Firmware, V340 17iwl Firmware, Yoga Slim 7 Pro 14ach5 D Firmware, Yoga Slim 7 Pro 14ach5 Od Firmware, Ideapad 3 14iil05 Firmware, Ideapad 3 14igl05 Firmware, Ideapad 3 15iil05 Firmware, Ideapad 5 15are05 Firmware, Ideapad Creator 5 15imh05 Firmware, Ideapad Gaming 3 15arh05 Firmware, Ideapad Gaming 3 15imh05 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before e8cn33ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14ada05 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before hbcn21ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14ada6 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before glcn43ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14alc6 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before dzcn42ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14are05 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before hbcn21ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15ada6 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before glcn43ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15alc6 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before dzcn42ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15are05 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before dvcn23ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15igl05 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before e8cn33ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 17ada05 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before hbcn21ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 17ada6 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before glcn43ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 17alc6 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before dzcn42ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 17are05 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before emcn52ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 17iil05 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before e8cn33ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15ada05 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before gfcn23ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo L3 15itl6 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before bgcn35ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo L340 15irh | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before atcn46ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo L340 15iwl | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before atcn46ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo L340 15iwl Touch | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before bgcn35ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo L340 17irh | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before atcn46ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo L340 17iwl | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before hhcn25ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16ach6 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before gkcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16ach6h | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn46ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16ith6 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn46ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 Pro 16ith6h | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before hhcn25ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ach6 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before g9cn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ach6a | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before gkcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ach6h | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn46ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ith6 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn46ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 15ith6h | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before hhcn25ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17ach6 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before gkcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17ach6h | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn46ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17ith6 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before h1cn46ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 5 17ith6h | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before gkcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 7 16achg6 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before gkcn51ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion 7 16ithg6 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before bhcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion Y540 15irh | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before bhcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion Y540 15irh Pg0 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before bhcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion Y540 17irh | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before bhcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion Y540 17irh Pg0 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before bhcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion Y545 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before bhcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion Y545 Pg0 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before bhcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion Y7000 2019 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before bhcn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Legion Y7000 2019 Pg0 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before bucn31ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S145 14api | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before aycn26ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S145 14ast | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before awcn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S145 14igm | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before dkcn54ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S145 14iil | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before bucn31ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S145 15api | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before aycn26ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S145 15ast | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before awcn28ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S145 15igm | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before dkcn54ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S145 15iil | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before cxcn34ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo S540 13api | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before glcn43ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V14 G2 Acl | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before e8cn33ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V14 Ada | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before dzcn42ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V14 Are | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before dvcn23ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V14 Igl | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before dkcn54ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V14 Iil | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before atcn46ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V140 15iwl | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before glcn43ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V15 G2 Alc | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before e8cn33ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V15 Ada | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before dvcn23ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V15 Igl | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before dkcn54ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V15 Iil | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before emcn52ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V17 Iil | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before atcn46ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo V340 17iwl | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before hecn24ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga Slim 7 Pro 14ach5 D | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before hecn24ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yoga Slim 7 Pro 14ach5 Od | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before dvcn23ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14iil05 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before emcn52ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 14igl05 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before emcn52ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 3 15iil05 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before e7cn44ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad 5 15are05 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before egcn36ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Creator 5 15imh05 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before fccn17ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Gaming 3 15arh05 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before egcn36ww |
| Running on/with | Platform Versions |
|---|---|
Lenovo Ideapad Gaming 3 15imh05 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.