SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-8334

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access.

MEDIUM 6.8EPSS 0.33%

Does this matter?

Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.

Description

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.33% probability · 26th percentile
CISA KEV
Not listed
Weakness
CWE-754
Affected
lenovo/thinkpad t495s firmware · lenovo/thinkpad x395 firmware · lenovo/thinkpad t495 firmware · lenovo/thinkpad a485 firmware · lenovo/thinkpad a285 firmware · lenovo/thinkpad a475 firmware · lenovo/thinkpad a275 firmware
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.