Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

Project Subscriptions

Vendors Products
730s-13iml Subscribe
730s-13iml Firmware Subscribe
Ideacentre Aio 5-24imb05 Subscribe
Ideacentre Aio 5-24imb05 Firmware Subscribe
Ideacentre Aio 5-74imb05 Subscribe
Ideacentre Aio 5-74imb05 Firmware Subscribe
Ideapad 1-11igl05 Subscribe
Ideapad 1-11igl05 Firmware Subscribe
Ideapad 1-14igl05 Subscribe
Ideapad 1-14igl05 Firmware Subscribe
Ideapad S940-14iil Subscribe
Ideapad S940-14iil Firmware Subscribe
Ideapad S940-14iwl Subscribe
Ideapad S940-14iwl Firmware Subscribe
Ideapad Slim 1-11ast-05 Subscribe
Ideapad Slim 1-11ast-05 Firmware Subscribe
Ideapad Slim 1-14ast-05 Subscribe
Ideapad Slim 1-14ast-05 Firmware Subscribe
Thinkpad Helix Subscribe
Thinkpad Helix Firmware Subscribe
Thinkpad T550 Subscribe
Thinkpad T550 Firmware Subscribe
Thinkpad W550s Subscribe
Thinkpad W550s Firmware Subscribe
Thinkpad X1 Carbon 3rd Gen Subscribe
Thinkpad X1 Carbon 3rd Gen Firmware Subscribe
Thinkpad X250 Subscribe
Thinkpad X250 Firmware Subscribe
Thinkpad Yoga 15 Subscribe
Thinkpad Yoga 15 Firmware Subscribe
V130-15igm Subscribe
V130-15igm Firmware Subscribe
V330-15ikb Subscribe
V330-15ikb Firmware Subscribe
V330-15isk Subscribe
V330-15isk Firmware Subscribe
Yoga S730-13iml Subscribe
Yoga S730-13iml Firmware Subscribe
Yoga S940-14iil Subscribe
Yoga S940-14iil Firmware Subscribe
Yoga S940-14iwl Subscribe
Yoga S940-14iwl Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-26776 Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-65529.


Workaround

No workaround given by the vendor.

History

Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-12-16T17:56:22.882Z

Reserved: 2021-03-19T00:00:00.000Z

Link: CVE-2021-3453

cve-icon Vulnrichment

Updated: 2024-08-03T16:53:17.675Z

cve-icon NVD

Status : Modified

Published: 2021-07-16T21:15:10.683

Modified: 2024-11-21T06:21:34.380

Link: CVE-2021-3453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses