CVE-2021-3971

CWE-4893 documents3 sources
Severity
6.7MEDIUM
EPSS
0.8%
top 25.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateApr 23

Description

A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages74 packages

CVEListV5lenovo/notebook_biosvarious
NVDlenovo/v14-ada_firmware< e8cn33ww
NVDlenovo/v14-are_firmware< dzcn42ww
NVDlenovo/v14-igl_firmware< dvcn23ww
NVDlenovo/v14-iil_firmware< dkcn54ww

🔴Vulnerability Details

2
GHSA
GHSA-v9mm-m35w-j8fm: A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included2022-04-23
CVEList
CVE-2021-3971: A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included2022-04-22