cbcvebase.
CVE-2021-3786
published 2021-11-12

CVE-2021-3786: A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data…

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.

Affected

137 ranges· showing 25
VendorProductVersion rangeFixed in
lenovoideapad_s940-14iwl_firmware<= 12.0.81.1753
lenovoideapad_yoga_s940-14iwl_firmware<= 12.0.81.1753
lenovonotebook_and_thinkpad_bios
lenovothinkpad_10_firmware< 2021-10-252021-10-25
lenovothinkpad_11e_3rd_gen_firmware< 2021-10-312021-10-31
lenovothinkpad_11e_4th_gen_firmware< 2021-10-312021-10-31
lenovothinkpad_11e_yoga_gen_6_firmware< 2021-10-312021-10-31
lenovothinkpad_13_gen_2_firmware< 2021-10-312021-10-31
lenovothinkpad_25_firmware< n1qet92wn1qet92w
lenovothinkpad_e14_firmware<= 2021-10-15
lenovothinkpad_e14_gen_2_firmware< 2021-10-152021-10-15
lenovothinkpad_e14_gen_3_firmware< 2021-10-152021-10-15
lenovothinkpad_e15_firmware< 2021-10-152021-10-15
lenovothinkpad_e15_gen_2_firmware< 2021-10-152021-10-15
lenovothinkpad_e15_gen_3_firmware< 2021-10-152021-10-15
lenovothinkpad_e470_firmware< 2021-10-152021-10-15
lenovothinkpad_e480_firmware< 2021-10-152021-10-15
lenovothinkpad_e490_firmware< 2021-10-152021-10-15
lenovothinkpad_e570_firmware< 2021-10-152021-10-15
lenovothinkpad_e580_firmware< 2021-10-152021-10-15
lenovothinkpad_e590_firmware< 2021-10-152021-10-15
lenovothinkpad_helix_firmware< n17etb6wn17etb6w
lenovothinkpad_l13_firmware< 2021-10-312021-10-31
lenovothinkpad_l13_gen_2_firmware< 2021-10-312021-10-31
lenovothinkpad_l13_yoga_firmware< 2021-10-312021-10-31