Description
Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
Published: 2021-07-16
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-65529.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-26776 Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
History

Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Lenovo 730s-13iml 730s-13iml Firmware Ideacentre Aio 5-24imb05 Ideacentre Aio 5-24imb05 Firmware Ideacentre Aio 5-74imb05 Ideacentre Aio 5-74imb05 Firmware Ideapad 1-11igl05 Ideapad 1-11igl05 Firmware Ideapad 1-14igl05 Ideapad 1-14igl05 Firmware Ideapad S940-14iil Ideapad S940-14iil Firmware Ideapad S940-14iwl Ideapad S940-14iwl Firmware Ideapad Slim 1-11ast-05 Ideapad Slim 1-11ast-05 Firmware Ideapad Slim 1-14ast-05 Ideapad Slim 1-14ast-05 Firmware Thinkpad Helix Thinkpad Helix Firmware Thinkpad T550 Thinkpad T550 Firmware Thinkpad W550s Thinkpad W550s Firmware Thinkpad X1 Carbon 3rd Gen Thinkpad X1 Carbon 3rd Gen Firmware Thinkpad X250 Thinkpad X250 Firmware Thinkpad Yoga 15 Thinkpad Yoga 15 Firmware V130-15igm V130-15igm Firmware V330-15ikb V330-15ikb Firmware V330-15isk V330-15isk Firmware Yoga S730-13iml Yoga S730-13iml Firmware Yoga S940-14iil Yoga S940-14iil Firmware Yoga S940-14iwl Yoga S940-14iwl Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-12-16T17:56:22.882Z

Reserved: 2021-03-19T00:00:00.000Z

Link: CVE-2021-3453

cve-icon Vulnrichment

Updated: 2024-08-03T16:53:17.675Z

cve-icon NVD

Status : Modified

Published: 2021-07-16T21:15:10.683

Modified: 2024-11-21T06:21:34.380

Link: CVE-2021-3453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses