CVE-2020-8320
published 2020-06-09CVE-2020-8320: An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
Affected
101 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | bios | — | — |
| lenovo | thinkpad_11e_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_11e_yoga_gen_6_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_13_2nd_gen_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_13_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_a275_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_a285_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_a475_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_a485_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e14_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e15_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e455_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e460_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e465_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e470_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e475_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e480_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e485_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e490_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e490s_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e555_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e560_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e560p_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e565_firmware | < 2020-07-10 | 2020-07-10 |
| lenovo | thinkpad_e570_firmware | < 2020-07-10 | 2020-07-10 |