SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3843

A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

MEDIUM 6.7EPSS 0.28%

Does this matter?

Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.

Description

A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.28% probability · 20th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
lenovo/thinkpad 11e 3rd gen firmware · lenovo/thinkpad 11e 4th gen i3 firmware · lenovo/thinkpad 11e 4th gen i7 firmware · lenovo/thinkpad 11e 4th gen i5 firmware · lenovo/thinkpad 11e 4th gen celeron firmware · lenovo/thinkpad 11e yoga gen 6 firmware · lenovo/thinkpad 13 gen 2 firmware · lenovo/thinkpad l13 firmware · lenovo/thinkpad l13 gen 2 firmware · lenovo/thinkpad l13 yoga firmware · lenovo/thinkpad l13 yoga gen 2 firmware · lenovo/thinkpad l14 gen 1 firmware · lenovo/thinkpad l14 firmware · lenovo/thinkpad l15 gen 1 firmware · lenovo/thinkpad l15 firmware · lenovo/thinkpad l380 firmware · lenovo/thinkpad l380 yoga firmware · lenovo/thinkpad l390 yoga firmware · lenovo/thinkpad l390 firmware · lenovo/thinkpad s5 2nd gen firmware · +9 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.