VulnerabilityModified
CVE-2021-3599
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
MEDIUM 6.7EPSS 0.29%
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.29% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- lenovo/thinkpad x380 yoga firmware · lenovo/thinkpad x1 fold gen 1 firmware · lenovo/thinkpad yoga 260 firmware · lenovo/thinkpad yoga 11e 3rd gen firmware · lenovo/thinkpad yoga 15 firmware · lenovo/thinkpad yoga 370 firmware · lenovo/thinkpad x12 detachable gen 1 firmware · lenovo/thinkpad x390 firmware · lenovo/thinkpad yoga 11e 4th gen firmware · lenovo/thinkpad yoga 11e 5th gen firmware · lenovo/thinkpad x250 firmware · lenovo/thinkpad x260 firmware · lenovo/thinkpad x390 yoga firmware · lenovo/thinkpad x280 firmware · lenovo/thinkpad x1 titanium firmware · lenovo/thinkpad x270 firmware · lenovo/thinkpad x1 carbon 5th gen kabylake firmware · lenovo/thinkpad x13 gen 1 firmware · lenovo/thinkpad x13 gen 2 firmware · lenovo/thinkpad x13 yoga gen 1 firmware · +40 more
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-67440Patch, Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-67440Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.