fkie_cve-2021-3843
Vulnerability from fkie_nvd
Published
2021-11-12 22:15
Modified
2024-11-21 06:22
Summary
A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Impacted products
Vendor Product Version
lenovo thinkpad_11e_3rd_gen_firmware *
lenovo thinkpad_11e_3rd_gen -
lenovo thinkpad_11e_3rd_gen_firmware *
lenovo thinkpad_11e_3rd_gen -
lenovo thinkpad_11e_4th_gen_i3_firmware *
lenovo thinkpad_11e_4th_gen_i3 -
lenovo thinkpad_11e_4th_gen_i7_firmware *
lenovo thinkpad_11e_4th_gen_i7 -
lenovo thinkpad_11e_4th_gen_i5_firmware *
lenovo thinkpad_11e_4th_gen_i5 -
lenovo thinkpad_11e_4th_gen_celeron_firmware *
lenovo thinkpad_11e_4th_gen_celeron -
lenovo thinkpad_11e_yoga_gen_6_firmware *
lenovo thinkpad_11e_yoga_gen_6 -
lenovo thinkpad_13_gen_2_firmware *
lenovo thinkpad_13_gen_2 -
lenovo thinkpad_l13_firmware *
lenovo thinkpad_l13 -
lenovo thinkpad_l13_gen_2_firmware *
lenovo thinkpad_l13_gen_2 -
lenovo thinkpad_l13_gen_2_firmware *
lenovo thinkpad_l13_gen_2 -
lenovo thinkpad_l13_yoga_firmware *
lenovo thinkpad_l13_yoga -
lenovo thinkpad_l13_yoga_gen_2_firmware *
lenovo thinkpad_l13_yoga_gen_2 -
lenovo thinkpad_l13_yoga_gen_2_firmware *
lenovo thinkpad_l13_yoga_gen_2 -
lenovo thinkpad_l14_gen_1_firmware *
lenovo thinkpad_l14_gen_1 -
lenovo thinkpad_l14_firmware *
lenovo thinkpad_l14 -
lenovo thinkpad_l15_gen_1_firmware *
lenovo thinkpad_l15_gen_1 -
lenovo thinkpad_l15_firmware *
lenovo thinkpad_l15 -
lenovo thinkpad_l380_firmware *
lenovo thinkpad_l380 -
lenovo thinkpad_l380_yoga_firmware *
lenovo thinkpad_l380_yoga -
lenovo thinkpad_l390_yoga_firmware *
lenovo thinkpad_l390_yoga -
lenovo thinkpad_l390_firmware *
lenovo thinkpad_l390 -
lenovo thinkpad_s5_2nd_gen_firmware *
lenovo thinkpad_s5_2nd_gen -
lenovo thinkpad_t460_firmware *
lenovo thinkpad_t460 -
lenovo thinkpad_s2_gen_6_firmware *
lenovo thinkpad_s2_gen_6 -
lenovo thinkpad_s2_yoga_gen_6_firmware *
lenovo thinkpad_s2_yoga_gen_6 -
lenovo thinkpad_x12_detachable_gen_1_firmware *
lenovo thinkpad_x12_detachable_gen_1 -
lenovo thinkpad_x260_firmware *
lenovo thinkpad_x260 -
lenovo thinkpad_x380_yoga_firmware *
lenovo thinkpad_x380_yoga -
lenovo thinkpad_x390_yoga_firmware *
lenovo thinkpad_x390_yoga -
lenovo thinkpad_11e_5th_gen_firmware *
lenovo thinkpad_11e_5th_gen -
lenovo thinkpad_11e_5th_gen_firmware *
lenovo thinkpad_yoga_370 -
lenovo thinkpad_x1_fold_gen_1_firmware *
lenovo thinkpad_x1_fold_gen_1 -



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_11e_3rd_gen_firmware:*:*:*:*:braswell:*:*:*",
              "matchCriteriaId": "EF33CA2E-BA9C-42CB-BFB8-67BFA996F823",
              "versionEndIncluding": "1.22",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_11e_3rd_gen:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C6C40A89-6683-4146-A5C2-46E253E33664",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_11e_3rd_gen_firmware:*:*:*:*:skylate:*:*:*",
              "matchCriteriaId": "AF5C9C0C-02C9-4E4B-A328-28ADD1C7C73C",
              "versionEndIncluding": "1.29",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_11e_3rd_gen:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C6C40A89-6683-4146-A5C2-46E253E33664",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_11e_4th_gen_i3_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "B7FC0313-CDB7-4FA8-A8EE-E2F56CA698C9",
              "versionEndIncluding": "1.22",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_11e_4th_gen_i3:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "5744944C-B5E0-4570-9C99-B266F3396684",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_11e_4th_gen_i7_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "B7D4AE53-712A-4FC5-8E2C-4EDFC5DE9084",
              "versionEndIncluding": "1.22",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_11e_4th_gen_i7:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "45A80116-86CA-4D26-A15A-406B785F7839",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_11e_4th_gen_i5_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "1110E47D-3E12-4D5D-96DE-851806E5B2C8",
              "versionEndIncluding": "1.22",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_11e_4th_gen_i5:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E629F33E-9826-455E-BFCE-1771388419B5",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_11e_4th_gen_celeron_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "9564E47E-13D4-49E3-BB84-839BCC5669F2",
              "versionEndIncluding": "1.27",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_11e_4th_gen_celeron:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "17D2BA00-3BE1-4C8A-B06B-37BACE73DD60",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_11e_yoga_gen_6_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "6EA1933F-E0CF-42E3-ABCF-F1E3A5E3F600",
              "versionEndIncluding": "1.12",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_11e_yoga_gen_6:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "4AA392C0-4D5A-4440-8910-C248F17077CC",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_13_gen_2_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "CED54838-0D2E-4A05-B1BC-B3076BCB4202",
              "versionEndIncluding": "1.29",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_13_gen_2:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "59C2F35D-79A1-4671-BA7E-4AAF2BA13744",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l13_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "1A667E70-ADCC-4414-B9B9-BFF7C7201501",
              "versionEndIncluding": "1.31",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l13:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "99429424-2602-458B-BB57-C2E161005587",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l13_gen_2_firmware:*:*:*:*:non-vpro:*:*:*",
              "matchCriteriaId": "F281D64C-C4E3-450C-9025-EC9D0774122F",
              "versionEndIncluding": "1.11",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l13_gen_2:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "3E560943-6A00-4423-91F3-FBBBBB978F6B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l13_gen_2_firmware:*:*:*:*:vpro:*:*:*",
              "matchCriteriaId": "EB897DCD-E534-4186-B067-B0EF3A6CD3B6",
              "versionEndIncluding": "1.08",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l13_gen_2:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "3E560943-6A00-4423-91F3-FBBBBB978F6B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l13_yoga_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "9A996F26-C250-4861-9B04-7757D3952D62",
              "versionEndIncluding": "1.31",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l13_yoga:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "1295E4F8-431A-43ED-8104-DBBD0CDB1978",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l13_yoga_gen_2_firmware:*:*:*:*:non-vpro:*:*:*",
              "matchCriteriaId": "0CE40F23-048C-41D7-866E-2277336298A5",
              "versionEndIncluding": "1.11",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l13_yoga_gen_2:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "0CB43443-ED65-4CF5-8FDA-3BCC1E2BD5A2",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l13_yoga_gen_2_firmware:*:*:*:*:vpro:*:*:*",
              "matchCriteriaId": "A2B92BB7-CE11-4C61-BE23-BE707CD8C5A5",
              "versionEndIncluding": "1.08",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l13_yoga_gen_2:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "0CB43443-ED65-4CF5-8FDA-3BCC1E2BD5A2",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l14_gen_1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "1826AF17-FEF9-483F-A074-047439C38B9D",
              "versionEndExcluding": "1.15",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l14_gen_1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D0528272-3E6D-41A6-B87D-66C3DB4E1B41",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l14_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "EBC186D1-5480-4534-A9C2-84DE077CEFFF",
              "versionEndExcluding": "1.20.1.17",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l14:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "724B10DF-7AA6-4541-A1F4-388E7BEB2319",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l15_gen_1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "809C9625-F900-4C40-999C-05B98080E4CB",
              "versionEndExcluding": "1.15",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l15_gen_1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "658E6C1D-7C9D-4934-A232-38F7A0809328",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l15_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "096AB67B-FEED-4127-8997-60900C46CE13",
              "versionEndExcluding": "1.20.1.17",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l15:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "65290880-A7DF-4350-8BBB-8175811EC15E",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l380_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "02E3C5A0-AF97-44B6-B1AB-2AD284214BC3",
              "versionEndIncluding": "1.26",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l380:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D0FFC7C4-2CAF-440A-8ED8-F25EA19F86C1",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l380_yoga_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "08745210-1EF0-487A-B77D-C8B4973E880D",
              "versionEndIncluding": "1.26",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l380_yoga:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "2187E37E-E3D6-467A-934C-D5613FBF8641",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l390_yoga_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "00C785F4-B1CD-40C0-A2CD-07FCDC41AFBE",
              "versionEndIncluding": "1.35",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l390_yoga:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "17DD928B-F0BF-44F1-9EA4-DC82233A2E69",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_l390_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "83C48F09-FB15-4ECC-B725-0155FAA5737B",
              "versionEndIncluding": "1.35",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_l390:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "072FAC2E-2349-465C-96C0-C24E3891A7B3",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_s5_2nd_gen_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "24FA1789-4C14-49A8-A229-5D5FABDB0F91",
              "versionEndIncluding": "1.28",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_s5_2nd_gen:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6C880E01-D245-4E17-939A-6FF0551D921E",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_t460_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "9E80FB3E-213D-49DB-B885-7AFCB7473FC0",
              "versionEndIncluding": "1.43.1.11",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_t460:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D86FD3AD-D731-4C30-8A72-EC1A45B203F0",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_s2_gen_6_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "DADDA0C3-0070-4260-B9D5-23B99C756357",
              "versionEndIncluding": "2021-09-30",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_s2_gen_6:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "FF3A2ACE-E9E9-4A93-9543-044096A8BAFE",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_s2_yoga_gen_6_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "047A9A31-89BB-4530-8848-DF5F5336FD7B",
              "versionEndIncluding": "2021-09-30",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_s2_yoga_gen_6:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "3B2279C8-0F44-4CA3-9AED-F31E3C3327D8",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_x12_detachable_gen_1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "707C8598-098F-44B1-8DB7-D5B7B8C84673",
              "versionEndExcluding": "1.16",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_x12_detachable_gen_1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A2439F63-731F-47A4-B625-B3520ECDA0B1",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_x260_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "B133AAA2-8104-4DB5-854F-B63A872D2AE3",
              "versionEndIncluding": "1.47\\/1.15",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_x260:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "08393A13-D68E-4042-B223-EF80E581EEBC",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_x380_yoga_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "5B16EE7F-8E0F-4790-8A4D-9D80D41D3621",
              "versionEndIncluding": "1.34",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_x380_yoga:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A5E1704F-6BB6-4B7C-ADE6-720533FB46E4",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_x390_yoga_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "A9788880-AE9D-47B3-8944-7D3FF46EF86E",
              "versionEndExcluding": "n2let87w",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_x390_yoga:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "30D40345-389F-4727-B549-1883C3454129",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_11e_5th_gen_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "B603071D-C4E4-4987-AA73-1EAEFAAE92AD",
              "versionEndIncluding": "1.13",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_11e_5th_gen:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8D46E4CE-05BB-498B-98C1-C641430AE0FB",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_11e_5th_gen_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "B603071D-C4E4-4987-AA73-1EAEFAAE92AD",
              "versionEndIncluding": "1.13",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_yoga_370:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "30B0E5C1-5A7B-4310-A4D3-A12E1F059568",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:thinkpad_x1_fold_gen_1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "D42E07CA-A44E-4AE1-A077-41A96ECCC91E",
              "versionEndExcluding": "n2pet50w",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkpad_x1_fold_gen_1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B6ACABAE-B074-4EE6-B969-ECD16CBB4224",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code."
    },
    {
      "lang": "es",
      "value": "Una posible vulnerabilidad en la funci\u00f3n SMI para acceder a la EEPROM en algunos modelos de ThinkPad puede permitir a un atacante con acceso local y privilegios elevados ejecutar c\u00f3digo arbitrario"
    }
  ],
  "id": "CVE-2021-3843",
  "lastModified": "2024-11-21T06:22:37.037",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "HIGH",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "LOCAL",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 7.2,
          "confidentialityImpact": "COMPLETE",
          "integrityImpact": "COMPLETE",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 10.0,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "LOCAL",
          "availabilityImpact": "HIGH",
          "baseScore": 6.7,
          "baseSeverity": "MEDIUM",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 0.8,
        "impactScore": 5.9,
        "source": "psirt@lenovo.com",
        "type": "Secondary"
      },
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "LOCAL",
          "availabilityImpact": "HIGH",
          "baseScore": 6.7,
          "baseSeverity": "MEDIUM",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 0.8,
        "impactScore": 5.9,
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  },
  "published": "2021-11-12T22:15:08.580",
  "references": [
    {
      "source": "psirt@lenovo.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "https://support.lenovo.com/us/en/product_security/LEN-72619"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "https://support.lenovo.com/us/en/product_security/LEN-72619"
    }
  ],
  "sourceIdentifier": "psirt@lenovo.com",
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ],
      "source": "psirt@lenovo.com",
      "type": "Secondary"
    },
    {
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…