VulnerabilityModified
CVE-2019-6188
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
CRITICAL 9.8EPSS 1.32%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- lenovo/510-15ikl firmware · lenovo/510s-08ikl firmware · lenovo/ideacentre 300-20ish firmware · lenovo/ideacentre 300s-11ish firmware · lenovo/ideacentre 310s-08asr firmware · lenovo/ideacentre 310s-08igm firmware · lenovo/ideacentre 510-15icb firmware · lenovo/ideacentre 510a-15icb firmware · lenovo/ideacentre 510s-08ish firmware · lenovo/ideacentre 700 firmware · lenovo/ideacentre 720-18apr firmware · lenovo/ideacentre 720-18icb firmware · lenovo/legion c530-19icb firmware · lenovo/legion c730-19ico firmware · lenovo/legion t530-28apr firmware · lenovo/legion t530-28apr reflash firmware · lenovo/legion t530-28icb firmware · lenovo/legion t530-28icb reflash firmware · lenovo/legion t730-28ico firmware · lenovo/legion y520t z370 firmware · +40 more
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-27714Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-27714Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.