Vulnerabilites related to Lenovo - ThinkPad T470p
CVE-2019-6188 (GCVE-0-2019-6188)
Vulnerability from cvelistv5
Published
2019-11-12 20:40
Modified
2024-08-04 20:16
Severity ?
CWE
  • Unauthorized access
Summary
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
References
Impacted products
Vendor Product Version
Lenovo ThinkPad T470p Version: unspecified   < R0FET50W
Create a notification for this product.
   Lenovo ThinkPad T460p Version: unspecified   < R07ET90W
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-04T20:16:24.282Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://support.lenovo.com/us/en/product_security/LEN-27714"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "ThinkPad T470p",
          "vendor": "Lenovo",
          "versions": [
            {
              "lessThan": "R0FET50W",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "ThinkPad T460p",
          "vendor": "Lenovo",
          "versions": [
            {
              "lessThan": "R07ET90W",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Unauthorized access",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2019-11-12T20:40:54",
        "orgId": "da227ddf-6e25-4b41-b023-0f976dcaca4b",
        "shortName": "lenovo"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://support.lenovo.com/us/en/product_security/LEN-27714"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "Update BIOS to version R07ET90W or higher for ThinkPad T460p\nUpdate BIOS to version R0FET50W or higher for ThinkPad T470p"
        }
      ],
      "source": {
        "advisory": "https://support.lenovo.com/us/en/product_security/LEN-27714",
        "discovery": "EXTERNAL"
      },
      "title": "ThinkPad T460p and T470p BIOS Tamper Mechanism",
      "x_generator": {
        "engine": "Vulnogram 0.0.8"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "psirt@lenovo.com",
          "ID": "CVE-2019-6188",
          "STATE": "PUBLIC",
          "TITLE": "ThinkPad T460p and T470p BIOS Tamper Mechanism"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "ThinkPad T470p",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "R0FET50W"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "ThinkPad T460p",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "R07ET90W"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Lenovo"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access."
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.8"
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Unauthorized access"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://support.lenovo.com/us/en/product_security/LEN-27714",
              "refsource": "MISC",
              "url": "https://support.lenovo.com/us/en/product_security/LEN-27714"
            }
          ]
        },
        "solution": [
          {
            "lang": "en",
            "value": "Update BIOS to version R07ET90W or higher for ThinkPad T460p\nUpdate BIOS to version R0FET50W or higher for ThinkPad T470p"
          }
        ],
        "source": {
          "advisory": "https://support.lenovo.com/us/en/product_security/LEN-27714",
          "discovery": "EXTERNAL"
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "da227ddf-6e25-4b41-b023-0f976dcaca4b",
    "assignerShortName": "lenovo",
    "cveId": "CVE-2019-6188",
    "datePublished": "2019-11-12T20:40:54",
    "dateReserved": "2019-01-11T00:00:00",
    "dateUpdated": "2024-08-04T20:16:24.282Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}