SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-6188

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.

CRITICAL 9.8EPSS 1.32%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.32% probability · 69th percentile
CISA KEV
Not listed
Affected
lenovo/510-15ikl firmware · lenovo/510s-08ikl firmware · lenovo/ideacentre 300-20ish firmware · lenovo/ideacentre 300s-11ish firmware · lenovo/ideacentre 310s-08asr firmware · lenovo/ideacentre 310s-08igm firmware · lenovo/ideacentre 510-15icb firmware · lenovo/ideacentre 510a-15icb firmware · lenovo/ideacentre 510s-08ish firmware · lenovo/ideacentre 700 firmware · lenovo/ideacentre 720-18apr firmware · lenovo/ideacentre 720-18icb firmware · lenovo/legion c530-19icb firmware · lenovo/legion c730-19ico firmware · lenovo/legion t530-28apr firmware · lenovo/legion t530-28apr reflash firmware · lenovo/legion t530-28icb firmware · lenovo/legion t530-28icb reflash firmware · lenovo/legion t730-28ico firmware · lenovo/legion y520t z370 firmware · +40 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.