SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-8320

An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

MEDIUM 6.8EPSS 0.28%

Does this matter?

Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.

Description

An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.28% probability · 21th percentile
CISA KEV
Not listed
Weakness
CWE-489, CWE-269
Affected
lenovo/thinkpad 11e yoga gen 6 firmware · lenovo/thinkpad 11e firmware · lenovo/thinkpad yoga 11e 3rd gen firmware · lenovo/thinkpad yoga 11e 4th gen firmware · lenovo/thinkpad yoga 11e 5th gen firmware · lenovo/thinkpad 13 2nd gen firmware · lenovo/thinkpad 13 firmware · lenovo/thinkpad a275 firmware · lenovo/thinkpad a285 firmware · lenovo/thinkpad a475 firmware · lenovo/thinkpad a485 firmware · lenovo/thinkpad e14 firmware · lenovo/thinkpad e15 firmware · lenovo/thinkpad r14 firmware · lenovo/thinkpad s3 gen 2 firmware · lenovo/thinkpad e455 firmware · lenovo/thinkpad e555 firmware · lenovo/thinkpad e460 firmware · lenovo/thinkpad e560 firmware · lenovo/thinkpad e465 firmware · +40 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.