CVE-2018-9069

MEDIUMCVSS 5.9/10EPSS 0.53%

Last modified

CVE-2018-9069 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.. EPSS estimates a 0.53% chance of exploitation in the next 30 days.

Description

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H

EPSS Probability
0.53%

40.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Hp310s-14isk Firmware< 1.15
Hp320-15ikbra Firmware< 6jcn24ww
Hp320-15ikbrn Firmware< 6jcn24ww
Hp320-15ikbrn Touch Firmware< 6jcn24ww
Hp320-17ikbrn< 2.09
Hp320s-14ikb< 2.09
Hp320s-15ikb Firmware< 2.09
Hp320s-15isk Firmware< 2wcn38ww
Hp510s-14isk Firmware< 1.15
Hp520-15ikbrn Firmware< 6jcn26ww
Hp520s-14ikb Firmware< 2.09
Hp710s Plus-13ikb 16g Firmware< 2.55
Hp710s Plus-3ikb Firmware< 2.55
HpXiaoxinair13ikbpro Firmware< 2.55
Hp710s Plus Touch-13ikb Firmware< 2.55
Hp720s-13ikb Firmware< 5scn38ww
HpB320-14ikb FirmwareAll versions
LenovoE42-80 Firmware< 2wcn38ww
LenovoE52-80 Firmware< 2wcn38ww
HpFlex 4-1470 Firmware< 1.15
HpFlex 5-1470 Firmware< 2.09
HpFlex 5-1570 Firmware< 2.09
HpIdeapad 2in1 14 FirmwareAll versions
HpLenovo Ideapad 320-14ikb\(I\+A\) FirmwareAll versions
HpLenovo Ideapad 320-14ikb\(I\+N\) FirmwareAll versions
HpLenovo Ideapad 320-15abr FirmwareAll versions
HpLenovo Ideapad 320-15ikb\(I\+N\) FirmwareAll versions
HpLenovo Ideapad 320s-14ikbr FirmwareAll versions
HpLenovo Ideapad 320s-15ikbr FirmwareAll versions
HpLenovo Ideapad 520s-14ikbr FirmwareAll versions
HpLenovo Ideapad 720s-14ikb Firmware< 6jcn26ww
HpLenovo Ideapad Flex 5-1470 Firmware< 6jcn26ww
HpLenovo Ideapad Flex 5-1570 Firmware< 6jcn26ww
HpLenovo Ideapad Y520-15ikbn FirmwareAll versions
HpLenovo Tianyi 310-14ikb FirmwareAll versions
HpLenovo Tianyi 310-15ikb FirmwareAll versions
HpLenovo Y520-15ikba Firmware< 5jcn25ww
HpLenovo Y520-15ikbm Firmware< 5jcn25ww
HpLenovo Yoga 520-14ikb Firmware< 6jcn26ww
HpLenovo Yoga 520-15ikb Firmware< 6jcn26ww
HpMiix 720-12ikb< 3scn66ww
HpNano110-14ikb FirmwareAll versions
HpNano110-15ikb Firmware< 5xcn24ww
HpRescuer R720-15ikbm Firmware< 5xcn24ww
HpRescuer Y520-15ikbm Firmware< 5xcn24ww
LenovoV310-14ikb Firmware< 2wcn38ww
LenovoV310-14isk Firmware< 4.07
LenovoV310-15ikb Firmware< 2wcn38ww
LenovoV310-15isk Firmware< 0zcn47ww
HpV330-14ikb Firmware< 4.07

Showing 50 of 68 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-9069?
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
How severe is CVE-2018-9069?
CVE-2018-9069 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 0.53% probability of exploitation in the next 30 days.
How do I fix CVE-2018-9069?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-9069?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST