CVE-2019-6156
Last modified
CVE-2019-6156 is a vulnerability of currently unknown severity. In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | 510-15ikl Firmware | All versions |
| Lenovo | 510s-08ikl Firmware | All versions |
| Lenovo | Ideacentre 300-20ish Firmware | All versions |
| Lenovo | Ideacentre 300s-11ish Firmware | All versions |
| Lenovo | Ideacentre 510-15icb Firmware | < o3qkt32a |
| Lenovo | Ideacentre 510a-15icb Firmware | < o3qkt32a |
| Lenovo | Ideacentre 510s-08ish Firmware | All versions |
| Lenovo | Ideacentre 620s-03ikl Firmware | All versions |
| Lenovo | Ideacentre 700 Firmware | < fwkt9aa |
| Lenovo | Ideacentre 720-18icb Firmware | < o3qkt32a |
| Lenovo | Legion C530-19icb Firmware | < o3lkt20a |
| Lenovo | Legion C730-19ico Firmware | < o3nkt20a |
| Lenovo | Legion T530-28icb Firmware | < o3lkt20a |
| Lenovo | Legion T730-28ico Firmware | < o3nkt20a |
| Lenovo | Legion Y520t Z370 Firmware | All versions |
| Lenovo | Legion Y720 Tower Firmware | All versions |
| Lenovo | Legion Y920 Tower Firmware | All versions |
| Lenovo | Lenovo 63 Firmware | All versions |
| Lenovo | H50-30g Desktop Firmware | All versions |
| Lenovo | M4500 Firmware | All versions |
| Lenovo | M4500 Id Firmware | All versions |
| Lenovo | M4550 Id Firmware | All versions |
| Lenovo | 530s-07icb Firmware | All versions |
| Lenovo | Qitian 4500 Firmware | All versions |
| Lenovo | Qitian B4550 Firmware | All versions |
| Lenovo | Qitian B4650 Firmware | All versions |
| Lenovo | Qitian M4550 Firmware | All versions |
| Lenovo | Qitian M4600 Firmware | All versions |
| Lenovo | Qitian M4650 Firmware | All versions |
| Lenovo | Qt M410 Firmware | All versions |
| Lenovo | Qt B415 Firmware | All versions |
| Lenovo | Qt M415 Firmware | All versions |
| Lenovo | Thinkcentre E73 \(Sff\) Firmware | All versions |
| Lenovo | Thinkcentre E73 \(Twr\) Firmware | All versions |
| Lenovo | Thinkcentre E73s Firmware | All versions |
| Lenovo | Thinkcentre E74 Firmware | All versions |
| Lenovo | Thinkcentre E74s Firmware | All versions |
| Lenovo | Thinkcentre E75t Firmware | All versions |
| Lenovo | Thinkcentre E75s Firmware | All versions |
| Lenovo | Thinkcentre E93 \(Sff\) Firmware | < fbktd5a |
| Lenovo | Thinkcentre E93 \(Twr\) Firmware | < fbktd5a |
| Lenovo | Thinkcentre M4500k Firmware | All versions |
| Lenovo | Thinkcentre M4500q Firmware | All versions |
| Lenovo | Thinkcentre M4500t Firmware | All versions |
| Lenovo | Thinkcentre M4500s Firmware | All versions |
| Lenovo | Thinkcentre M4600t Firmware | All versions |
| Lenovo | Thinkcentre M4600s Firmware | All versions |
| Lenovo | Thinkcentre M610 Firmware | < m1akt3fa |
| Lenovo | Thinkcentre M6500t Firmware | < fbktd5a |
| Lenovo | Thinkcentre M6500s Firmware | < fbktd5a |
Showing 50 of 178 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/solutions/LEN-26332Patch, Vendor Advisory
- https://support.lenovo.com/solutions/LEN-26332Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6156?
How severe is CVE-2019-6156?
How do I fix CVE-2019-6156?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-6150Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-6151Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-6152Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-6153Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-6154A DLL search path vulnerability was reported in Lenovo Boota…5.3
- CVE-2019-6155A potential vulnerability was found in an SMI handler in var…4.1
- CVE-2019-6157In various firmware versions of Lenovo System x, the integra…6.5
- CVE-2019-6158An internal product security audit of Lenovo XClarity Admini…8.7
- CVE-2019-6159A stored cross-site scripting (XSS) vulnerability exists in …6.1
- CVE-2019-6160A vulnerability in various versions of Iomega and LenovoEMC …8.8
- CVE-2019-6161An internal product security audit discovered a session hand…7.5
- CVE-2019-6162Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2019-6156?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
