SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-6172

A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.

MEDIUM 6.4EPSS 0.33%

Does this matter?

Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.

Description

A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.

CVSS 3.1
6.4 MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.33% probability · 26th percentile
CISA KEV
Not listed
Affected
lenovo/510-15ikl firmware · lenovo/510s-08ikl firmware · lenovo/ideacentre 300-20ish firmware · lenovo/ideacentre 300s-11ish firmware · lenovo/ideacentre 310s-08asr firmware · lenovo/ideacentre 310s-08igm firmware · lenovo/ideacentre 510-15icb firmware · lenovo/ideacentre 510a-15icb firmware · lenovo/ideacentre 510s-08ish firmware · lenovo/ideacentre 700 firmware · lenovo/ideacentre 720-18apr firmware · lenovo/ideacentre 720-18icb firmware · lenovo/legion c530-19icb firmware · lenovo/legion c730-19ico firmware · lenovo/legion t530-28apr firmware · lenovo/legion t530-28apr reflash firmware · lenovo/legion t530-28icb firmware · lenovo/legion t530-28icb reflash firmware · lenovo/legion t730-28ico firmware · lenovo/legion y520t z370 firmware · +40 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.