Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Thinkcentre M80s
Subscribe
Thinkcentre M80s Firmware
Subscribe
Thinkcentre M80t
Subscribe
Thinkcentre M80t Firmware
Subscribe
Thinkcentre M90s
Subscribe
Thinkcentre M90s Firmware
Subscribe
Thinkcentre M90t
Subscribe
Thinkcentre M90t Firmware
Subscribe
Thinkcentre M910z
Subscribe
Thinkcentre M910z Firmware
Subscribe
Thinkcentre M920q
Subscribe
Thinkcentre M920q Firmware
Subscribe
Thinkcentre M920s
Subscribe
Thinkcentre M920s Firmware
Subscribe
Thinkcentre M920t
Subscribe
Thinkcentre M920t Firmware
Subscribe
Thinkcentre M920z
Subscribe
Thinkcentre M920z Firmware
Subscribe
Thinkstation P330 Tiny
Subscribe
Thinkstation P330 Tiny Firmware
Subscribe
Thinkstation P330s
Subscribe
Thinkstation P330s Firmware
Subscribe
Thinkstation P330t
Subscribe
Thinkstation P330t Firmware
Subscribe
Thinkstation P340s
Subscribe
Thinkstation P340s Firmware
Subscribe
Thinkstation P340t
Subscribe
Thinkstation P340t Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-29220 | Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT. |
Fixes
Solution
Use the IntelĀ® AMT Configuration Utility 12.2.0.150 or later to verify the EHBC is enabled. Check EHBC Status: ACUConfig.exe /verbose /output console Status To disable Intel EHBC: ACUConfig.exe DisableEhbcState
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-44725 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-04T09:56:28.333Z
Reserved: 2020-01-28T00:00:00
Link: CVE-2020-8353
No data.
Status : Modified
Published: 2020-11-11T18:15:11.767
Modified: 2024-11-21T05:38:45.917
Link: CVE-2020-8353
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD