CVE-2018-9069

CWE-362Race Condition3 documents3 sources
Severity
5.9MEDIUM
EPSS
0.2%
top 56.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 2
Latest updateMay 13

Description

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:HExploitability: 0.7 | Impact: 5.2

Affected Packages56 packages

🔴Vulnerability Details

2
GHSA
GHSA-p7mj-q6cv-6qw2: In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, pote2022-05-13
CVEList
BIOS Write Protection Race Condition2018-10-02
CVE-2018-9069 (MEDIUM CVSS 5.9) | In some Lenovo IdeaPad consumer not | cvebase.io