fkie_cve-2021-3719
Vulnerability from fkie_nvd
Published
2021-11-12 22:15
Modified
2024-11-21 06:22
Summary
A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_e93_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "F534F97A-0288-4015-8C8B-B98AE66CB812",
              "versionEndExcluding": "fbktdfa",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_e93:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DA9110B9-D4E6-4DEC-B0B9-DE4641117B54",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m600_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "69F0297B-815E-4912-A23B-A4F38BB43BAF",
              "versionEndExcluding": "m00kt65a",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m600:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DCA4E481-3FE3-4AC5-BDEA-EF0C667E331E",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m700_tiny_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "118DA580-F89C-40FF-930C-E974C13108EE",
              "versionEndExcluding": "fwktb9a",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m700_tiny:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "AE20DD1E-5C2C-4253-B71E-529D699FB8D0",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m73_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "C5FA79F6-A8EF-4B91-9C11-F03DF14A4313",
              "versionEndExcluding": "fhkt86a",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m73:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6FB24CE6-E1F1-4151-9228-61DCD08E9D01",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m73p_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "2BDBA965-81EB-4898-9C06-A8D917841553",
              "versionEndExcluding": "fbktdfa",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m73p:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "CB7C0580-76A1-41C4-B743-96000853236B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m800_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "4E0468FF-B7A5-4199-8A5A-CD26C7992EB2",
              "versionEndExcluding": "fwktb9a",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m800:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B97FE070-E06D-433B-AAC9-A2460E404B94",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m818z_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "54C60F2A-20C6-44D9-AEF4-92CEBCAB1B6C",
              "versionEndExcluding": "m1ekt23a",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m818z:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "37E62D35-9270-4959-A9C2-97E3F9F0719A",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m83_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "A37FFBD9-559D-4798-BFF5-94BD14EB0FD4",
              "versionEndExcluding": "fbktdfa",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m83:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "9BB1BF39-4D09-4133-88CB-AD9E1271EFF0",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m900_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "5C6746A2-953E-4F8A-AEC7-0FD2CC688777",
              "versionEndExcluding": "fwktb9a",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m900:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "ADC80C43-18AF-433D-AA51-F473B8501329",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m900x_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "94EB1312-08C4-4018-AEEA-6305716BF89C",
              "versionEndExcluding": "fwktb9a",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m900x:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "261F2F75-E0E4-4318-BB7B-065EC466D671",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m93_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "F5C2FD29-75C8-46BE-878F-590A9DB316AF",
              "versionEndExcluding": "fbktdfa",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m93:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6340A351-D5A0-46D2-BF97-412DD66BDE65",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m93p_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "58AA9D3A-6CB8-4715-8394-4573EE16E293",
              "versionEndExcluding": "fbktdfa",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m93p:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "11A2CF02-7D37-4C2A-ABB5-0F072BF7C739",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m4500q_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "E375987D-4349-4285-856A-22D60E52523C",
              "versionEndExcluding": "fhkt86a",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m4500q:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C0B588AF-BB3E-4A22-8197-0450B307F38B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m6500t\\/s_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "817002BF-7E5C-43EA-BA8A-28B1DC908CE7",
              "versionEndExcluding": "fbktdfa",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m6500t\\/s:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E2BD6A2B-9A26-410E-A4D0-CCCCDECB7036",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_m8500t\\/s_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "328A37CD-78D2-4B20-AF44-CC1AD8395556",
              "versionEndExcluding": "fbktdfa",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_m8500t\\/s:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "9DC5D34D-72DB-455E-9A01-9066BE4D3670",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkcentre_x1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "75BA83EE-4F80-499B-9634-E350088D87D5",
              "versionEndExcluding": "m0hkt50a",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkcentre_x1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "62066C05-06E3-4443-B217-98FB5038FCA4",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkstation_p300_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "8618E20B-AF94-47FD-86EC-C661DE63FEF6",
              "versionEndExcluding": "fbktdfa",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkstation_p300:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "EDCE0A0B-C9EB-402A-B43B-6B7670E2BF73",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkstation_p500_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "D7D7EE98-676F-474A-BBBF-E71B128FBCB8",
              "versionEndExcluding": "a4ktaba",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkstation_p500:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B4CA9A54-00A0-4569-9AE0-6AE02A039600",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkstation_p700_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "F2D8F272-C7C2-45BC-B83F-0430A6CB6AEA",
              "versionEndExcluding": "a5ktaba",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkstation_p700:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "BA54FF9E-3B77-4B09-A77B-D7F522A69326",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkstation_p900_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "F06F1ABF-130E-416F-993B-25E3F6832B72",
              "versionEndExcluding": "a6ktaba",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkstation_p900:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "5FB1B208-2854-4F95-BAB0-661442FEC477",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code."
    },
    {
      "lang": "es",
      "value": "Una posible vulnerabilidad en la funci\u00f3n SMI callback que guarda y restaura las tablas de scripts de arranque usadas para reanudar desde el estado de suspensi\u00f3n en algunos modelos ThinkCentre y ThinkStation puede permitir a un atacante con acceso local y privilegios elevados ejecutar c\u00f3digo arbitrario"
    }
  ],
  "id": "CVE-2021-3719",
  "lastModified": "2024-11-21T06:22:14.657",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "HIGH",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "LOCAL",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 7.2,
          "confidentialityImpact": "COMPLETE",
          "integrityImpact": "COMPLETE",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 10.0,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "LOCAL",
          "availabilityImpact": "HIGH",
          "baseScore": 6.7,
          "baseSeverity": "MEDIUM",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 0.8,
        "impactScore": 5.9,
        "source": "psirt@lenovo.com",
        "type": "Secondary"
      },
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "LOCAL",
          "availabilityImpact": "HIGH",
          "baseScore": 6.7,
          "baseSeverity": "MEDIUM",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 0.8,
        "impactScore": 5.9,
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  },
  "published": "2021-11-12T22:15:07.957",
  "references": [
    {
      "source": "psirt@lenovo.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "https://support.lenovo.com/us/en/product_security/LEN-67440"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "https://support.lenovo.com/us/en/product_security/LEN-67440"
    }
  ],
  "sourceIdentifier": "psirt@lenovo.com",
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ],
      "source": "psirt@lenovo.com",
      "type": "Secondary"
    },
    {
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…