SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-6156

In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash.

LOW 3.3EPSS 0.24%

Does this matter?

Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.

Description

In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.

CVSS 3.0
3.3 LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
0.24% probability · 15th percentile
CISA KEV
Not listed
Weakness
CWE-667
Affected
lenovo/510-15ikl firmware · lenovo/510s-08ikl firmware · lenovo/ideacentre 300-20ish firmware · lenovo/ideacentre 300s-11ish firmware · lenovo/ideacentre 510-15icb firmware · lenovo/ideacentre 510a-15icb firmware · lenovo/ideacentre 510s-08ish firmware · lenovo/ideacentre 620s-03ikl firmware · lenovo/ideacentre 700 firmware · lenovo/ideacentre 720-18icb firmware · lenovo/legion c530-19icb firmware · lenovo/legion c730-19ico firmware · lenovo/legion t530-28icb firmware · lenovo/legion t730-28ico firmware · lenovo/legion y520t z370 firmware · lenovo/legion y720 tower firmware · lenovo/legion y920 tower firmware · lenovo/lenovo 63 firmware · lenovo/h50-30g desktop firmware · lenovo/m4500 firmware · +40 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.