cbcvebase.
CVE-2021-3718
published 2021-11-12

CVE-2021-3718: A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in…

PriorityP411medium4.6CVSS 3.1
AVPACLPRNUINSUCNINAH
EPSS
0.21%
11.3th percentile
A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
lenovothinkpad_11e_3rd_gen_firmware<= 1.22
lenovothinkpad_11e_3rd_gen_firmware<= 1.29
lenovothinkpad_11e_4th_gen_celeron_firmware<= 1.27
lenovothinkpad_11e_4th_gen_i3_firmware<= 1.22
lenovothinkpad_11e_4th_gen_i5_firmware<= 1.22
lenovothinkpad_11e_4th_gen_i7_firmware<= 1.22
lenovothinkpad_11e_5th_gen_firmware<= 1.13
lenovothinkpad_11e_yoga_gen_6_firmware<= 1.12
lenovothinkpad_13_gen_2_firmware<= 1.29
lenovothinkpad_bios
lenovothinkpad_e490_firmware<= 1.30
lenovothinkpad_e490s_firmware<= 1.30
lenovothinkpad_e590_firmware<= 1.30
lenovothinkpad_l13_firmware<= 1.31
lenovothinkpad_l13_gen_2_firmware<= 1.11
lenovothinkpad_l13_gen_2_firmware<= 1.08
lenovothinkpad_l13_yoga_firmware<= 1.31
lenovothinkpad_l13_yoga_gen_2_firmware<= 1.11
lenovothinkpad_l13_yoga_gen_2_firmware<= 1.08
lenovothinkpad_l14_firmware< 1.20.1.171.20.1.17
lenovothinkpad_l14_gen_1_firmware< 1.151.15
lenovothinkpad_l15_firmware< 1.20.1.171.20.1.17
lenovothinkpad_l15_gen_1_firmware< 1.151.15
lenovothinkpad_l380_firmware<= 1.26
lenovothinkpad_l380_yoga_firmware<= 1.26

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.