SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3599

A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

MEDIUM 6.7EPSS 0.29%

Does this matter?

Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.

Description

A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.29% probability · 21th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
lenovo/thinkpad x380 yoga firmware · lenovo/thinkpad x1 fold gen 1 firmware · lenovo/thinkpad yoga 260 firmware · lenovo/thinkpad yoga 11e 3rd gen firmware · lenovo/thinkpad yoga 15 firmware · lenovo/thinkpad yoga 370 firmware · lenovo/thinkpad x12 detachable gen 1 firmware · lenovo/thinkpad x390 firmware · lenovo/thinkpad yoga 11e 4th gen firmware · lenovo/thinkpad yoga 11e 5th gen firmware · lenovo/thinkpad x250 firmware · lenovo/thinkpad x260 firmware · lenovo/thinkpad x390 yoga firmware · lenovo/thinkpad x280 firmware · lenovo/thinkpad x1 titanium firmware · lenovo/thinkpad x270 firmware · lenovo/thinkpad x1 carbon 5th gen kabylake firmware · lenovo/thinkpad x13 gen 1 firmware · lenovo/thinkpad x13 gen 2 firmware · lenovo/thinkpad x13 yoga gen 1 firmware · +40 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.