CVE-2020-8335
published 2020-09-01CVE-2020-8335: The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS…
PriorityP425medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.31%
23.3th percentile
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | thinkpad_a275_firmware | < 2020-08-30 | 2020-08-30 |
| lenovo | thinkpad_a285_bios | >= unspecified < r0xuj70w | r0xuj70w |
| lenovo | thinkpad_a285_firmware | < 2020-08-30 | 2020-08-30 |
| lenovo | thinkpad_a475_firmware | < 2020-08-30 | 2020-08-30 |
| lenovo | thinkpad_a485_bios | >= unspecified < r0wuj65w | r0wuj65w |
| lenovo | thinkpad_a485_firmware | < 2020-08-30 | 2020-08-30 |
| lenovo | thinkpad_t495_bios | >= unspecified < r12uj55w | r12uj55w |
| lenovo | thinkpad_t495_drift_firmware | < 2020-08-30 | 2020-08-30 |
| lenovo | thinkpad_t495s_jazz_firmware | < 2020-08-30 | 2020-08-30 |
| lenovo | thinkpad_t495s_x395_bios | >= unspecified < r13uj47w | r13uj47w |
| lenovo | thinkpad_x1_carbon_firmware | < n14et54w | n14et54w |
| lenovo | thinkpad_x395_firmware | < 2020-08-30 | 2020-08-30 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-09-01
Published