A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Thinkpad 11e 3rd Gen
Subscribe
Thinkpad 11e 3rd Gen Firmware
Subscribe
Thinkpad 11e 4th Gen Celeron
Subscribe
Thinkpad 11e 4th Gen Celeron Firmware
Subscribe
Thinkpad 11e 4th Gen I3
Subscribe
Thinkpad 11e 4th Gen I3 Firmware
Subscribe
Thinkpad 11e 4th Gen I5
Subscribe
Thinkpad 11e 4th Gen I5 Firmware
Subscribe
Thinkpad 11e 4th Gen I7
Subscribe
Thinkpad 11e 4th Gen I7 Firmware
Subscribe
Thinkpad 11e 5th Gen
Subscribe
Thinkpad 11e 5th Gen Firmware
Subscribe
Thinkpad 11e Yoga Gen 6
Subscribe
Thinkpad 11e Yoga Gen 6 Firmware
Subscribe
Thinkpad 13 Gen 2
Subscribe
Thinkpad 13 Gen 2 Firmware
Subscribe
Thinkpad L13
Subscribe
Thinkpad L13 Firmware
Subscribe
Thinkpad L13 Gen 2
Subscribe
Thinkpad L13 Gen 2 Firmware
Subscribe
Thinkpad L13 Yoga
Subscribe
Thinkpad L13 Yoga Firmware
Subscribe
Thinkpad L13 Yoga Gen 2
Subscribe
Thinkpad L13 Yoga Gen 2 Firmware
Subscribe
Thinkpad L14
Subscribe
Thinkpad L14 Firmware
Subscribe
Thinkpad L14 Gen 1
Subscribe
Thinkpad L14 Gen 1 Firmware
Subscribe
Thinkpad L15
Subscribe
Thinkpad L15 Firmware
Subscribe
Thinkpad L15 Gen 1
Subscribe
Thinkpad L15 Gen 1 Firmware
Subscribe
Thinkpad L380
Subscribe
Thinkpad L380 Firmware
Subscribe
Thinkpad L380 Yoga
Subscribe
Thinkpad L380 Yoga Firmware
Subscribe
Thinkpad L390
Subscribe
Thinkpad L390 Firmware
Subscribe
Thinkpad L390 Yoga
Subscribe
Thinkpad L390 Yoga Firmware
Subscribe
Thinkpad S2 Gen 6
Subscribe
Thinkpad S2 Gen 6 Firmware
Subscribe
Thinkpad S2 Yoga Gen 6
Subscribe
Thinkpad S2 Yoga Gen 6 Firmware
Subscribe
Thinkpad S5 2nd Gen
Subscribe
Thinkpad S5 2nd Gen Firmware
Subscribe
Thinkpad T460
Subscribe
Thinkpad T460 Firmware
Subscribe
Thinkpad X12 Detachable Gen 1
Subscribe
Thinkpad X12 Detachable Gen 1 Firmware
Subscribe
Thinkpad X1 Fold Gen 1
Subscribe
Thinkpad X1 Fold Gen 1 Firmware
Subscribe
Thinkpad X260
Subscribe
Thinkpad X260 Firmware
Subscribe
Thinkpad X380 Yoga
Subscribe
Thinkpad X380 Yoga Firmware
Subscribe
Thinkpad X390 Yoga
Subscribe
Thinkpad X390 Yoga Firmware
Subscribe
Thinkpad Yoga 370
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-27086 | A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code. |
Fixes
Solution
Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-72619.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-72619 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-03T17:09:09.580Z
Reserved: 2021-09-30T00:00:00
Link: CVE-2021-3843
No data.
Status : Modified
Published: 2021-11-12T22:15:08.580
Modified: 2024-11-21T06:22:37.037
Link: CVE-2021-3843
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD