SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3786

A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.

MEDIUM 5.5EPSS 0.23%

Does this matter?

Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.

Description

A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.23% probability · 14th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
lenovo/thinkpad x380 yoga firmware · lenovo/thinkpad x1 fold gen 1 firmware · lenovo/thinkpad yoga 260 firmware · lenovo/thinkpad yoga 11e 3rd gen firmware · lenovo/thinkpad yoga 15 firmware · lenovo/thinkpad yoga 370 firmware · lenovo/thinkpad x12 detachable gen 1 firmware · lenovo/thinkpad x390 firmware · lenovo/thinkpad yoga 11e 4th gen firmware · lenovo/thinkpad yoga 11e 5th gen firmware · lenovo/thinkpad x250 firmware · lenovo/thinkpad x260 firmware · lenovo/thinkpad x390 yoga firmware · lenovo/thinkpad x280 firmware · lenovo/thinkpad x1 titanium firmware · lenovo/thinkpad x270 firmware · lenovo/thinkpad x1 carbon 5th gen kabylake firmware · lenovo/thinkpad x13 gen 1 firmware · lenovo/thinkpad x13 gen 2 firmware · lenovo/thinkpad x13 yoga gen 1 firmware · +40 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.