cbcvebase.
CVE-2020-8341
published 2020-09-01

CVE-2020-8341: In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of…

low2.4CVSS 3.1
AVPACLPRNUINSUCNILAN
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.

Affected

10 ranges
VendorProductVersion rangeFixed in
lenovothinkpad
lenovothinkpad_t490_firmware< n2iet90wn2iet90w
lenovothinkpad_t490_firmware< n2ret16wn2ret16w
lenovothinkpad_t490s_firmware< n2jet89wn2jet89w
lenovothinkpad_t495_drift_firmware< 2020-08-302020-08-30
lenovothinkpad_t590_firmware< n2iet90wn2iet90w
lenovothinkpad_x1_carbon_firmware< n2het54wn2het54w
lenovothinkpad_x1_yoga_firmware< n2het54wn2het54w
lenovothinkpad_x390_firmware< n2jet89wn2jet89w
lenovothinkpad_x390_firmware< n2set18wn2set18w