SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-9069

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.

MEDIUM 5.9EPSS 0.53%

Does this matter?

Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.

Description

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
EPSS
0.53% probability · 43th percentile
CISA KEV
Not listed
Weakness
CWE-362
Affected
hp/310s-14isk firmware · hp/320-15ikbra firmware · hp/320-15ikbrn firmware · hp/320-15ikbrn touch firmware · hp/320-17ikbrn · hp/320s-14ikb · hp/320s-15ikb firmware · hp/320s-15isk firmware · hp/510s-14isk firmware · hp/520-15ikbrn firmware · hp/520s-14ikb firmware · hp/710s plus-13ikb 16g firmware · hp/710s plus-3ikb firmware · hp/xiaoxinair13ikbpro firmware · hp/710s plus touch-13ikb firmware · hp/720s-13ikb firmware · hp/b320-14ikb firmware · lenovo/e42-80 firmware · lenovo/e52-80 firmware · hp/flex 4-1470 firmware · +40 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.