Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.

Project Subscriptions

Vendors Products
Thinkcentre M80s Subscribe
Thinkcentre M80s Firmware Subscribe
Thinkcentre M80t Subscribe
Thinkcentre M80t Firmware Subscribe
Thinkcentre M90s Subscribe
Thinkcentre M90s Firmware Subscribe
Thinkcentre M90t Subscribe
Thinkcentre M90t Firmware Subscribe
Thinkcentre M910z Subscribe
Thinkcentre M910z Firmware Subscribe
Thinkcentre M920q Subscribe
Thinkcentre M920q Firmware Subscribe
Thinkcentre M920s Subscribe
Thinkcentre M920s Firmware Subscribe
Thinkcentre M920t Subscribe
Thinkcentre M920t Firmware Subscribe
Thinkcentre M920z Subscribe
Thinkcentre M920z Firmware Subscribe
Thinkstation P330 Tiny Subscribe
Thinkstation P330 Tiny Firmware Subscribe
Thinkstation P330s Subscribe
Thinkstation P330s Firmware Subscribe
Thinkstation P330t Subscribe
Thinkstation P330t Firmware Subscribe
Thinkstation P340s Subscribe
Thinkstation P340s Firmware Subscribe
Thinkstation P340t Subscribe
Thinkstation P340t Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-29220 Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.
Fixes

Solution

Use the IntelĀ® AMT Configuration Utility 12.2.0.150 or later to verify the EHBC is enabled. Check EHBC Status: ACUConfig.exe /verbose /output console Status To disable Intel EHBC: ACUConfig.exe DisableEhbcState


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-04T09:56:28.333Z

Reserved: 2020-01-28T00:00:00

Link: CVE-2020-8353

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-11T18:15:11.767

Modified: 2024-11-21T05:38:45.917

Link: CVE-2020-8353

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses