CVE-2021-3599

Severity
6.7MEDIUM
EPSS
0.0%
top 88.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages134 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7jgm-fxw4-3rp9: A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and2022-05-24
CVEList
CVE-2021-3599: A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and2021-11-12
CVE-2021-3599 (MEDIUM CVSS 6.7) | A potential vulnerability in the SM | cvebase.io