Home
MEDIUM: 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
various
affected
Description
A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.
Problem types
CWE-1419: Incorrect Initialization of Resource
Product status
various
Credits
Lenovo thanks Krzysztof Okupski, Enrique Nissim, Joseph Tartaro of IOActive for reporting this vulnerability.
References
support.lenovo.com/us/en/product_security/LEN-141775
support.lenovo.com/us/en/product_security/LEN-141775