CVE-2019-6170
Last modified
CVE-2019-6170 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | 510-15ikl Firmware | All versions |
| Lenovo | 510s-08ikl Firmware | All versions |
| Lenovo | Ideacentre 300-20ish Firmware | All versions |
| Lenovo | Ideacentre 300s-11ish Firmware | All versions |
| Lenovo | Ideacentre 310s-08asr Firmware | All versions |
| Lenovo | Ideacentre 310s-08igm Firmware | All versions |
| Lenovo | Ideacentre 510-15icb Firmware | All versions |
| Lenovo | Ideacentre 510a-15icb Firmware | All versions |
| Lenovo | Ideacentre 510s-08ish Firmware | All versions |
| Lenovo | Ideacentre 700 Firmware | All versions |
| Lenovo | Ideacentre 720-18apr Firmware | All versions |
| Lenovo | Ideacentre 720-18icb Firmware | All versions |
| Lenovo | Legion C530-19icb Firmware | All versions |
| Lenovo | Legion C730-19ico Firmware | All versions |
| Lenovo | Legion T530-28apr Firmware | All versions |
| Lenovo | Legion T530-28apr Reflash Firmware | All versions |
| Lenovo | Legion T530-28icb Firmware | All versions |
| Lenovo | Legion T530-28icb Reflash Firmware | All versions |
| Lenovo | Legion T730-28ico Firmware | All versions |
| Lenovo | Legion Y520t Z370 Firmware | All versions |
| Lenovo | 63 Firmware | All versions |
| Lenovo | H50-30g Desktop Firmware | All versions |
| Lenovo | M4500 Firmware | All versions |
| Lenovo | M4500 Id Firmware | All versions |
| Lenovo | M4550 Id Firmware | All versions |
| Lenovo | V330-15igm Firmware | All versions |
| Lenovo | V530s-07icb Firmware | All versions |
| Lenovo | Qitian 4500 Firmware | All versions |
| Lenovo | Qitian B4550 Firmware | All versions |
| Lenovo | Qitian B4650 Firmware | All versions |
| Lenovo | Qitian B5900 Firmware | All versions |
| Lenovo | Qitian M4550 Firmware | All versions |
| Lenovo | Qitian M4600 Firmware | All versions |
| Lenovo | Qitian M4650 Firmware | All versions |
| Lenovo | Qt M410 Firmware | All versions |
| Lenovo | Qt B415 Firmware | All versions |
| Lenovo | Qt M415 Firmware | All versions |
| Lenovo | Thinkcentre E73 Firmware | All versions |
| Lenovo | Thinkcentre E73s Firmware | All versions |
| Lenovo | Thinkcentre E74 Firmware | All versions |
| Lenovo | Thinkcentre E74s Firmware | All versions |
| Lenovo | Thinkcentre E75t Firmware | All versions |
| Lenovo | Thinkcentre E75s Firmware | All versions |
| Lenovo | Thinkcentre E93 Firmware | All versions |
| Lenovo | Thinkcentre M4500k Firmware | All versions |
| Lenovo | Thinkcentre M4500q Firmware | All versions |
| Lenovo | Thinkcentre M4500t Firmware | All versions |
| Lenovo | Thinkcentre M4500s Firmware | All versions |
| Lenovo | Thinkcentre M4600t Firmware | All versions |
| Lenovo | Thinkcentre M4600s Firmware | All versions |
Showing 50 of 392 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/us/en/product_security/LEN-27714Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-27714Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6170?
How severe is CVE-2019-6170?
How do I fix CVE-2019-6170?
Are you affected by CVE-2019-6170?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
