CVE-2021-3452
published 2021-07-16CVE-2021-3452: A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges…
PriorityP430medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.27%
19.1th percentile
A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | thinkpad_bios | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M1 (CVE-2020-3452)
suricata·2021-10-27·CVSS 7.5
CVE-2020-3452 [HIGH] ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M1 (CVE-2020-3452)
ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M1 (CVE-2020-3452)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M1 (CVE-2020-3452)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/translation-table?"; nocase; fast_pattern; content:"type=mst"; content:"textdomain="; content:"&lang="; content:"|2e 2e|"; reference:url,twitter.com/aboul3la/status/1286012324722155525; reference:cve,2020-3452; classtype:attempted-admin; sid:2034262; rev:1; metadata:created_at 2021_10_27, cve CVE_2020_3452, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_10_27, mitre_tactic
Suricata
ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M2 (CVE-2020-3452)
suricata·2021-10-27·CVSS 7.5
CVE-2020-3452 [HIGH] ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M2 (CVE-2020-3452)
ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M2 (CVE-2020-3452)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M2 (CVE-2020-3452)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/oem-customization?"; nocase; fast_pattern; content:"app=AnyConnect"; nocase; content:"type=oem"; nocase; content:"platform="; nocase; content:"resource-type="; nocase; content:"name="; nocase; content:"|2e 2e|"; reference:url,twitter.com/aboul3la/status/1286141887716503553; reference:cve,2020-3452; classtype:attempted-admin; sid:2034263; rev:1; metadata:created_at 2021_10_27, cve CVE_2020_3452, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag CIS
No public exploits indexed.
No writeups or analysis indexed.
2021-07-16
Published