cbcvebase.
CVE-2018-9069
published 2018-10-02

CVE-2018-9069: In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially…

PriorityP426medium5.9CVSS 3.1
AVNACHPRHUINSUCNIHAH
EPSS
0.53%
41.4th percentile
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.

Affected

56 ranges· showing 25
VendorProductVersion rangeFixed in
hp310s-14isk_firmware< 1.151.15
hp320-15ikbra_firmware< 6jcn24ww6jcn24ww
hp320-15ikbrn_firmware< 6jcn24ww6jcn24ww
hp320-15ikbrn_touch_firmware< 6jcn24ww6jcn24ww
hp320-17ikbrn< 2.092.09
hp320s-14ikb< 2.092.09
hp320s-15ikb_firmware< 2.092.09
hp320s-15isk_firmware< 2wcn38ww2wcn38ww
hp510s-14isk_firmware< 1.151.15
hp520-15ikbrn_firmware< 6jcn26ww6jcn26ww
hp520s-14ikb_firmware< 2.092.09
hp7000-15_u42_firmware< 2.092.09
hp7000_u42_firmware< 2.092.09
hp710s_plus-13ikb_16g_firmware< 2.552.55
hp710s_plus-3ikb_firmware< 2.552.55
hp710s_plus_touch-13ikb_firmware< 2.552.55
hp720s-13ikb_firmware< 5scn38ww5scn38ww
hpe43-80_kbl_firmware< 4.074.07
hpflex_4-1470_firmware< 1.151.15
hpflex_5-1470_firmware< 2.092.09
hpflex_5-1570_firmware< 2.092.09
hplenovo_ideapad_720s-14ikb_firmware< 6jcn26ww6jcn26ww
hplenovo_ideapad_flex_5-1470_firmware< 6jcn26ww6jcn26ww
hplenovo_ideapad_flex_5-1570_firmware< 6jcn26ww6jcn26ww
hplenovo_v720-14_firmware< 2.122.12

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
nvdv2.07.0HIGHAV:N/AC:M/Au:S/C:N/I:P/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.