VulnerabilityModified
CVE-2021-3970
A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code.
MEDIUM 6.7EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- lenovo/ideapad 3-14ada05 firmware · lenovo/ideapad 3-14ada6 firmware · lenovo/ideapad 3-14alc6 firmware · lenovo/ideapad 3-14are05 firmware · lenovo/ideapad 3-15ada6 firmware · lenovo/ideapad 3-15alc6 firmware · lenovo/ideapad 3-15are05 firmware · lenovo/ideapad 3-15igl05 firmware · lenovo/ideapad 3-17ada05 firmware · lenovo/ideapad 3-17ada6 firmware · lenovo/ideapad 3-17alc6 firmware · lenovo/ideapad 3-17are05 firmware · lenovo/ideapad 3-17iil05 firmware · lenovo/ideapad 3-17itl6 firmware · lenovo/ideapad 3-15ada05 firmware · lenovo/l3 15iml05 firmware · lenovo/l3-15itl6 firmware · lenovo/l340-15irh firmware · lenovo/l340-15iwl firmware · lenovo/l340-15iwl touch firmware · +40 more
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-73440Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-73440Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.