CVE-2021-3453

CWE-6933 documents3 sources
Severity
4.6MEDIUM
EPSS
0.0%
top 85.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 16
Latest updateMay 24

Description

Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages9 packages

🔴Vulnerability Details

2
GHSA
GHSA-rm7h-f39f-xc8f: Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physica2022-05-24
CVEList
CVE-2021-3453: Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physica2021-07-16
CVE-2021-3453 (MEDIUM CVSS 4.6) | Some Lenovo Notebook | cvebase.io