VulnerabilityModified
CVE-2019-6170
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
MEDIUM 6.4EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
- CVSS 3.1
- 6.4 MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Affected
- lenovo/510-15ikl firmware · lenovo/510s-08ikl firmware · lenovo/ideacentre 300-20ish firmware · lenovo/ideacentre 300s-11ish firmware · lenovo/ideacentre 310s-08asr firmware · lenovo/ideacentre 310s-08igm firmware · lenovo/ideacentre 510-15icb firmware · lenovo/ideacentre 510a-15icb firmware · lenovo/ideacentre 510s-08ish firmware · lenovo/ideacentre 700 firmware · lenovo/ideacentre 720-18apr firmware · lenovo/ideacentre 720-18icb firmware · lenovo/legion c530-19icb firmware · lenovo/legion c730-19ico firmware · lenovo/legion t530-28apr firmware · lenovo/legion t530-28apr reflash firmware · lenovo/legion t530-28icb firmware · lenovo/legion t530-28icb reflash firmware · lenovo/legion t730-28ico firmware · lenovo/legion y520t z370 firmware · +40 more
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-27714Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-27714Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.