VulnerabilityModified
CVE-2021-3719
A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute…
MEDIUM 6.7EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- lenovo/thinkcentre e93 firmware · lenovo/thinkcentre m600 firmware · lenovo/thinkcentre m700 tiny firmware · lenovo/thinkcentre m73 firmware · lenovo/thinkcentre m73p firmware · lenovo/thinkcentre m800 firmware · lenovo/thinkcentre m818z firmware · lenovo/thinkcentre m83 firmware · lenovo/thinkcentre m900 firmware · lenovo/thinkcentre m900x firmware · lenovo/thinkcentre m93 firmware · lenovo/thinkcentre m93p firmware · lenovo/thinkcentre m4500q firmware · lenovo/thinkcentre m6500t\/s firmware · lenovo/thinkcentre m8500t\/s firmware · lenovo/thinkcentre x1 firmware · lenovo/thinkstation p300 firmware · lenovo/thinkstation p500 firmware · lenovo/thinkstation p700 firmware · lenovo/thinkstation p900 firmware
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-67440Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-67440Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.