SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3971

A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region…

MEDIUM 6.7EPSS 1.29%

Does this matter?

Lower severity and a low EPSS score (1.29%). Track it; it rarely justifies an emergency change on its own.

Description

A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
1.29% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-489
Affected
lenovo/ideapad 3-14ada05 firmware · lenovo/ideapad 3-14ada6 firmware · lenovo/ideapad 3-14alc6 firmware · lenovo/ideapad 3-14are05 firmware · lenovo/ideapad 3-15ada6 firmware · lenovo/ideapad 3-15alc6 firmware · lenovo/ideapad 3-15are05 firmware · lenovo/ideapad 3-15igl05 firmware · lenovo/ideapad 3-17ada05 firmware · lenovo/ideapad 3-17ada6 firmware · lenovo/ideapad 3-17alc6 firmware · lenovo/ideapad 3-17are05 firmware · lenovo/ideapad 3-17iil05 firmware · lenovo/ideapad 3-15ada05 firmware · lenovo/l3-15itl6 firmware · lenovo/l340-15irh firmware · lenovo/l340-15iwl firmware · lenovo/l340-15iwl touch firmware · lenovo/l340-17irh firmware · lenovo/l340-17iwl firmware · +40 more
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.