SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3453

Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

MEDIUM 4.6EPSS 0.24%

Does this matter?

Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.

Description

Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

CVSS 3.1
4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
0.24% probability · 15th percentile
CISA KEV
Not listed
Weakness
CWE-693
Affected
lenovo/thinkpad helix firmware · lenovo/thinkpad t550 firmware · lenovo/thinkpad w550s firmware · lenovo/thinkpad x1 carbon 3rd gen firmware · lenovo/thinkpad x250 firmware · lenovo/thinkpad yoga 15 firmware · lenovo/730s-13iml firmware · lenovo/ideapad 1-11igl05 firmware · lenovo/ideapad 1-14igl05 firmware · lenovo/ideapad s940-14iil firmware · lenovo/ideapad s940-14iwl firmware · lenovo/ideapad slim 1-11ast-05 firmware · lenovo/ideapad slim 1-14ast-05 firmware · lenovo/v130-15igm firmware · lenovo/v330-15ikb firmware · lenovo/v330-15isk firmware · lenovo/yoga s730-13iml firmware · lenovo/yoga s940-14iil firmware · lenovo/yoga s940-14iwl firmware · lenovo/ideacentre aio 5-24imb05 firmware · +1 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.