CVE-2021-3786
published 2021-11-12CVE-2021-3786: A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.23%
13.2th percentile
A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.
Affected
137 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | ideapad_s940-14iwl_firmware | <= 12.0.81.1753 | — |
| lenovo | ideapad_yoga_s940-14iwl_firmware | <= 12.0.81.1753 | — |
| lenovo | notebook_and_thinkpad_bios | — | — |
| lenovo | thinkpad_10_firmware | < 2021-10-25 | 2021-10-25 |
| lenovo | thinkpad_11e_3rd_gen_firmware | < 2021-10-31 | 2021-10-31 |
| lenovo | thinkpad_11e_4th_gen_firmware | < 2021-10-31 | 2021-10-31 |
| lenovo | thinkpad_11e_yoga_gen_6_firmware | < 2021-10-31 | 2021-10-31 |
| lenovo | thinkpad_13_gen_2_firmware | < 2021-10-31 | 2021-10-31 |
| lenovo | thinkpad_25_firmware | < n1qet92w | n1qet92w |
| lenovo | thinkpad_e14_firmware | <= 2021-10-15 | — |
| lenovo | thinkpad_e14_gen_2_firmware | < 2021-10-15 | 2021-10-15 |
| lenovo | thinkpad_e14_gen_3_firmware | < 2021-10-15 | 2021-10-15 |
| lenovo | thinkpad_e15_firmware | < 2021-10-15 | 2021-10-15 |
| lenovo | thinkpad_e15_gen_2_firmware | < 2021-10-15 | 2021-10-15 |
| lenovo | thinkpad_e15_gen_3_firmware | < 2021-10-15 | 2021-10-15 |
| lenovo | thinkpad_e470_firmware | < 2021-10-15 | 2021-10-15 |
| lenovo | thinkpad_e480_firmware | < 2021-10-15 | 2021-10-15 |
| lenovo | thinkpad_e490_firmware | < 2021-10-15 | 2021-10-15 |
| lenovo | thinkpad_e570_firmware | < 2021-10-15 | 2021-10-15 |
| lenovo | thinkpad_e580_firmware | < 2021-10-15 | 2021-10-15 |
| lenovo | thinkpad_e590_firmware | < 2021-10-15 | 2021-10-15 |
| lenovo | thinkpad_helix_firmware | < n17etb6w | n17etb6w |
| lenovo | thinkpad_l13_firmware | < 2021-10-31 | 2021-10-31 |
| lenovo | thinkpad_l13_gen_2_firmware | < 2021-10-31 | 2021-10-31 |
| lenovo | thinkpad_l13_yoga_firmware | < 2021-10-31 | 2021-10-31 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Sentinelone
Another Brick in the Wall: Uncovering SMM Vulnerabilities in HP Firmware
blogs_sentinelone·2022-03-10·CVSS 5.5
CVE-2022-23956 [MEDIUM] Another Brick in the Wall: Uncovering SMM Vulnerabilities in HP Firmware
By Assaf Carlsbad & Itai Liba
## Executive Summary
- SentinelLabs has discovered 6 high severity flaws in HP’s UEFI firmware impacting HP laptops and desktops.
- Attackers may exploit these vulnerabilities to locally escalate to SMM privileges.
- SentinelLabs findings were proactively reported to HP on Aug 18, 2021, and are tracked as:
- CVE-2022-23956, marked with a CVSS score of 8.2
- CVE-2022-23953, marked with a CVSS score of 7.9
- CVE-2022-23954, marked with a CVSS score of 7.9
- CVE-2022-23955, marked with a CVSS score of 7.9
- CVE-2022-23957, marked with a CVSS score of 7.9
- CVE-2022-23958, marked with a CVSS score of 7.9
- HP has released a security update to its customers to address these vulnerabilities.
- At this time, SentinelOne has not discovered evidence of in-the-wild
Sentinelone
Another Brick in the Wall: Uncovering SMM Vulnerabilities in HP Firmware
blogs_sentinelone·2022-03-10·CVSS 5.5
CVE-2022-23956 [MEDIUM] Another Brick in the Wall: Uncovering SMM Vulnerabilities in HP Firmware
## Another Brick in the Wall: Uncovering SMM Vulnerabilities in HP Firmware
By Assaf Carlsbad & Itai Liba
## Executive Summary
SentinelLabs has discovered 6 high severity flaws in HP’s UEFI firmware impacting HP laptops and desktops.
Attackers may exploit these vulnerabilities to locally escalate to SMM privileges.
CVE-2022-23956, marked with a CVSS score of 8.2
CVE-2022-23953, marked with a CVSS score of 7.9
CVE-2022-23954, marked with a CVSS score of 7.9
CVE-2022-23955, marked with a CVSS score of 7.9
CVE-2022-23957, marked with a CVSS score of 7.9
CVE-2022-23958, marked with a CVSS score of 7.9
HP has released a security update to its customers to address these vulnerabilities.
At this time, SentinelOne has not discovered evidence of in-the-wild abuse.
Hello and welcome bac
2021-11-12
Published