CVE-2021-3786

Severity
5.5MEDIUM
EPSS
0.0%
top 86.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6

Affected Packages134 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mxm2-jrgh-833g: A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak o2022-05-24
CVEList
CVE-2021-3786: A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak o2021-11-12
CVE-2021-3786 (MEDIUM CVSS 5.5) | A potential vulnerability in the SM | cvebase.io