Description
A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Published: 2022-04-22
Score: 6.7 Medium
EPSS: 3.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-73440.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-27177 A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
History

No history.

Subscriptions

Lenovo Ideapad 3-14ada05 Ideapad 3-14ada05 Firmware Ideapad 3-14ada6 Ideapad 3-14ada6 Firmware Ideapad 3-14alc6 Ideapad 3-14alc6 Firmware Ideapad 3-14are05 Ideapad 3-14are05 Firmware Ideapad 3-14igl05 Ideapad 3-14igl05 Firmware Ideapad 3-14iil05 Ideapad 3-14iil05 Firmware Ideapad 3-14iml05 Ideapad 3-14iml05 Firmware Ideapad 3-14itl05 Ideapad 3-14itl05 Firmware Ideapad 3-14itl6 Ideapad 3-14itl6 Firmware Ideapad 3-15ada05 Ideapad 3-15ada05 Firmware Ideapad 3-15ada6 Ideapad 3-15ada6 Firmware Ideapad 3-15alc6 Ideapad 3-15alc6 Firmware Ideapad 3-15are05 Ideapad 3-15are05 Firmware Ideapad 3-15igl05 Ideapad 3-15igl05 Firmware Ideapad 3-15iil05 Ideapad 3-15iil05 Firmware Ideapad 3-15iml05 Ideapad 3-15iml05 Firmware Ideapad 3-15itl05 Ideapad 3-15itl05 Firmware Ideapad 3-15itl6 Ideapad 3-15itl6 Firmware Ideapad 3-17ada05 Ideapad 3-17ada05 Firmware Ideapad 3-17ada6 Ideapad 3-17ada6 Firmware Ideapad 3-17alc6 Ideapad 3-17alc6 Firmware Ideapad 3-17are05 Ideapad 3-17are05 Firmware Ideapad 3-17iil05 Ideapad 3-17iil05 Firmware Ideapad 3-17iml05 Ideapad 3-17iml05 Firmware Ideapad 3-17itl6 Ideapad 3-17itl6 Firmware Ideapad 5-15are05 Ideapad 5-15are05 Firmware Ideapad 5-15iil05 Ideapad 5-15iil05 Firmware Ideapad Creator 5-15imh05 Ideapad Creator 5-15imh05 Firmware Ideapad Gaming 3-15arh05 Ideapad Gaming 3-15arh05 Firmware Ideapad Gaming 3-15imh05 Ideapad Gaming 3-15imh05 Firmware L3-15itl6 L3-15itl6 Firmware L340-15irh L340-15irh Firmware L340-15iwl L340-15iwl Firmware L340-15iwl Touch L340-15iwl Touch Firmware L340-17irh L340-17irh Firmware L340-17iwl L340-17iwl Firmware L3 15iml05 L3 15iml05 Firmware Legion 5-15ach6 Legion 5-15ach6 Firmware Legion 5-15ach6a Legion 5-15ach6a Firmware Legion 5-15ach6h Legion 5-15ach6h Firmware Legion 5-15imh6 Legion 5-15imh6 Firmware Legion 5-15ith6 Legion 5-15ith6 Firmware Legion 5-15ith6h Legion 5-15ith6h Firmware Legion 5-17ach6 Legion 5-17ach6 Firmware Legion 5-17ach6h Legion 5-17ach6h Firmware Legion 5-17ith6 Legion 5-17ith6 Firmware Legion 5-17ith6h Legion 5-17ith6h Firmware Legion 5 Pro-16ach6 Legion 5 Pro-16ach6 Firmware Legion 5 Pro-16ach6h Legion 5 Pro-16ach6h Firmware Legion 5 Pro-16ith6 Legion 5 Pro-16ith6 Firmware Legion 5 Pro-16ith6h Legion 5 Pro-16ith6h Firmware Legion 7-16achg6 Legion 7-16achg6 Firmware Legion 7-16ithg6 Legion 7-16ithg6 Firmware Legion S7-15ach6 Legion S7-15ach6 Firmware Legion Y540-15irh Legion Y540-15irh-pg0 Legion Y540-15irh-pg0 Firmware Legion Y540-15irh Firmware Legion Y540-17irh Legion Y540-17irh-pg0 Legion Y540-17irh-pg0 Firmware Legion Y540-17irh Firmware Legion Y545 Legion Y545-pg0 Legion Y545-pg0 Firmware Legion Y545 Firmware Legion Y7000-2019 Legion Y7000-2019-pg0 Legion Y7000-2019-pg0 Firmware Legion Y7000-2019 Firmware S145-14api S145-14api Firmware S145-14ast S145-14ast Firmware S145-14igm S145-14igm Firmware S145-14iil S145-14iil Firmware S145-15api S145-15api Firmware S145-15ast S145-15ast Firmware S145-15igm S145-15igm Firmware S145-15iil S145-15iil Firmware S14 G2 Itl S14 G2 Itl Firmware S540-13api S540-13api Firmware S540-13iml S540-13iml Firmware Slim 7 Pro-14ihu5 Slim 7 Pro-14ihu5 Firmware Slim 9-14itl05 Slim 9-14itl05 Firmware V14-ada V14-ada Firmware V14-are V14-are Firmware V14-igl V14-igl Firmware V14-iil V14-iil Firmware V140-15iwl V140-15iwl Firmware V14 G1-iml V14 G1-iml Firmware V14 G2-acl V14 G2-acl Firmware V14 G2-itl V14 G2-itl Firmware V15-ada V15-ada Firmware V15-igl V15-igl Firmware V15-iil V15-iil Firmware V15 G1-iml V15 G1-iml Firmware V15 G2-alc V15 G2-alc Firmware V15 G2-itl V15 G2-itl Firmware V17-iil V17-iil Firmware V17 G2-itl V17 G2-itl Firmware V340-17iwl V340-17iwl Firmware Yoga 7-14acn6 Yoga 7-14acn6 Firmware Yoga C740-14iml Yoga C740-14iml Firmware Yoga C740-15iml Yoga C740-15iml Firmware Yoga C940-14iil Yoga C940-14iil Firmware Yoga Slim 7 Pro-14ach5 Yoga Slim 7 Pro-14ach5 D Yoga Slim 7 Pro-14ach5 D Firmware Yoga Slim 7 Pro-14ach5 Firmware Yoga Slim 7 Pro-14ach5 O Yoga Slim 7 Pro-14ach5 O Firmware Yoga Slim 7 Pro-14ach5 Od Yoga Slim 7 Pro-14ach5 Od Firmware Yoga Slim 7 Pro-14arh5 Yoga Slim 7 Pro-14arh5 Firmware Yoga Slim 7 Pro-14ihu5 Yoga Slim 7 Pro-14ihu5 Firmware Yoga Slim 7 Pro-14ihu5 O Yoga Slim 7 Pro-14ihu5 O Firmware Yoga Slim 7 Pro-14itl5 Yoga Slim 7 Pro-14itl5 Firmware Yoga Slim 9-14itl05 Yoga Slim 9-14itl05 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:09:09.723Z

Reserved: 2021-11-17T00:00:00.000Z

Link: CVE-2021-3972

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-22T21:15:09.883

Modified: 2024-11-21T06:23:16.210

Link: CVE-2021-3972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses