cbcvebase.
CVE-2019-6156
published 2019-04-10

CVE-2019-6156: In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of…

low3.3CVSS 3.0
AVLACLPRLUINSUCNILAN
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.

Affected

75 ranges· showing 25
VendorProductVersion rangeFixed in
lenovo330-14igm_firmware< 7xcn30ww7xcn30ww
lenovo330-15igm_firmware< 7xcn30ww7xcn30ww
lenovoaio300-23isu_firmware< o1lkt46ao1lkt46a
lenovoaio_910-27ish_firmware< o37kt13ao37kt13a
lenovobios
lenovoideacentre_510-15icb_firmware< o3qkt32ao3qkt32a
lenovoideacentre_510a-15icb_firmware< o3qkt32ao3qkt32a
lenovoideacentre_520s-23iku_firmware< o34kt23ao34kt23a
lenovoideacentre_700_firmware< fwkt9aafwkt9aa
lenovoideacentre_720-18icb_firmware< o3qkt32ao3qkt32a
lenovoideacentre_730s-24ikb_firmware< o3wkt15ao3wkt15a
lenovolegion_c530-19icb_firmware< o3lkt20ao3lkt20a
lenovolegion_c730-19ico_firmware< o3nkt20ao3nkt20a
lenovolegion_t530-28icb_firmware< o3lkt20ao3lkt20a
lenovolegion_t730-28ico_firmware< o3nkt20ao3nkt20a
lenovothinkcentre_e93_firmware< fbktd5afbktd5a
lenovothinkcentre_e95z_firmware< m1lkt20am1lkt20a
lenovothinkcentre_e96z_firmware< m26kt11am26kt11a
lenovothinkcentre_m610_firmware< m1akt3fam1akt3fa
lenovothinkcentre_m6500s_firmware< fbktd5afbktd5a
lenovothinkcentre_m6500t_firmware< fbktd5afbktd5a
lenovothinkcentre_m6600_firmware< fwkt9aafwkt9aa
lenovothinkcentre_m6600q_firmware< fwkt9aafwkt9aa
lenovothinkcentre_m6600s_firmware< fwkt9aafwkt9aa
lenovothinkcentre_m6600t_firmware< fwkt9aafwkt9aa