Description
A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Published: 2021-11-12
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-72619.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-27086 A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
History

No history.

Subscriptions

Lenovo Thinkpad 11e 3rd Gen Thinkpad 11e 3rd Gen Firmware Thinkpad 11e 4th Gen Celeron Thinkpad 11e 4th Gen Celeron Firmware Thinkpad 11e 4th Gen I3 Thinkpad 11e 4th Gen I3 Firmware Thinkpad 11e 4th Gen I5 Thinkpad 11e 4th Gen I5 Firmware Thinkpad 11e 4th Gen I7 Thinkpad 11e 4th Gen I7 Firmware Thinkpad 11e 5th Gen Thinkpad 11e 5th Gen Firmware Thinkpad 11e Yoga Gen 6 Thinkpad 11e Yoga Gen 6 Firmware Thinkpad 13 Gen 2 Thinkpad 13 Gen 2 Firmware Thinkpad L13 Thinkpad L13 Firmware Thinkpad L13 Gen 2 Thinkpad L13 Gen 2 Firmware Thinkpad L13 Yoga Thinkpad L13 Yoga Firmware Thinkpad L13 Yoga Gen 2 Thinkpad L13 Yoga Gen 2 Firmware Thinkpad L14 Thinkpad L14 Firmware Thinkpad L14 Gen 1 Thinkpad L14 Gen 1 Firmware Thinkpad L15 Thinkpad L15 Firmware Thinkpad L15 Gen 1 Thinkpad L15 Gen 1 Firmware Thinkpad L380 Thinkpad L380 Firmware Thinkpad L380 Yoga Thinkpad L380 Yoga Firmware Thinkpad L390 Thinkpad L390 Firmware Thinkpad L390 Yoga Thinkpad L390 Yoga Firmware Thinkpad S2 Gen 6 Thinkpad S2 Gen 6 Firmware Thinkpad S2 Yoga Gen 6 Thinkpad S2 Yoga Gen 6 Firmware Thinkpad S5 2nd Gen Thinkpad S5 2nd Gen Firmware Thinkpad T460 Thinkpad T460 Firmware Thinkpad X12 Detachable Gen 1 Thinkpad X12 Detachable Gen 1 Firmware Thinkpad X1 Fold Gen 1 Thinkpad X1 Fold Gen 1 Firmware Thinkpad X260 Thinkpad X260 Firmware Thinkpad X380 Yoga Thinkpad X380 Yoga Firmware Thinkpad X390 Yoga Thinkpad X390 Yoga Firmware Thinkpad Yoga 370
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:09:09.580Z

Reserved: 2021-09-30T00:00:00.000Z

Link: CVE-2021-3843

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-12T22:15:08.580

Modified: 2024-11-21T06:22:37.037

Link: CVE-2021-3843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses