Lenovo Bios vulnerabilities
32 known vulnerabilities affecting lenovo/bios.
Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM25LOW2
Vulnerabilities
Page 2 of 2
CVE-2023-45075P4MEDIUMCVSS 6.7vvarious2023-11-08
CVE-2023-45075 [MEDIUM] CWE-125 CVE-2023-45075: A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local at
A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
nvd
CVE-2019-6171P4MEDIUMCVSS 6.8vvarious2019-08-19
CVE-2019-6171 [MEDIUM] CVE-2019-6171: A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a u
A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
nvd
CVE-2020-8320P4MEDIUMCVSS 6.8vvarious2020-06-09
CVE-2020-8320 [MEDIUM] CWE-489 CVE-2020-8320: An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
nvd
CVE-2020-8334P4MEDIUMCVSS 6.8vvarious2020-06-09
CVE-2020-8334 [MEDIUM] CWE-754 CVE-2020-8334: The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A2
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access.
nvd
CVE-2020-8336P4MEDIUMCVSS 6.8vvarious2020-06-09
CVE-2020-8336 [MEDIUM] CVE-2020-8336: Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.
nvd
CVE-2019-6190P4MEDIUMCVSS 5.5vvarious2020-02-14
CVE-2019-6190 [MEDIUM] CWE-665 CVE-2019-6190: Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BI
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.
nvd
CVE-2021-3453P4MEDIUMCVSS 4.6vvarious2021-07-16
CVE-2021-3453 [MEDIUM] CWE-693 CVE-2021-3453: Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Bo
Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
nvd
CVE-2022-40134P4MEDIUMCVSS 4.4vvarious2023-01-30
CVE-2022-40134 [MEDIUM] CWE-125 CVE-2022-40134: An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
nvd
CVE-2022-40135P4MEDIUMCVSS 4.4vvarious2023-01-30
CVE-2022-40135 [MEDIUM] CWE-125 CVE-2022-40135: An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
nvd
CVE-2022-40136P4MEDIUMCVSS 4.4vvarious2023-01-30
CVE-2022-40136 [MEDIUM] CWE-125 CVE-2022-40136: An information leak vulnerability in SMI Handler used to configure platform settings over WMI in som
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
nvd
CVE-2019-6156P4LOWCVSS 3.3vvarious2019-04-10
CVE-2019-6156 [LOW] CWE-667 CVE-2019-6156: In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this prov
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not i
nvd
CVE-2020-8352P4LOWCVSS 2.4≥ unspecified, < various2020-11-11
CVE-2020-8352 [LOW] CWE-358 CVE-2020-8352: In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA
In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.
nvd
← Previous2 / 2