A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-15738 A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
Fixes

Solution

Update to the version of BIOS (or later) described for your system in the Product Impact section of LEN-27764.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-16T20:03:17.346Z

Reserved: 2019-01-11T00:00:00

Link: CVE-2019-6171

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-19T15:15:11.653

Modified: 2024-11-21T04:46:05.243

Link: CVE-2019-6171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.