CVE-2020-8320

MEDIUMCVSS 6.8/10EPSS 0.27%

Last modified

CVE-2020-8320 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.

Description

An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

Metrics

CVSS 3.1
6.8/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.27%

18.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoThinkpad 11e Yoga Gen 6 Firmware< 2020-07-10
LenovoThinkpad 11e Firmware< 2020-07-10
LenovoThinkpad Yoga 11e 3rd Gen Firmware< 2020-07-10
LenovoThinkpad Yoga 11e 4th Gen Firmware< 2020-07-10
LenovoThinkpad Yoga 11e 5th Gen Firmware< 2020-07-10
LenovoThinkpad 13 2nd Gen Firmware< 2020-07-10
LenovoThinkpad 13 Firmware< 2020-07-10
LenovoThinkpad A275 Firmware< 2020-07-10
LenovoThinkpad A285 Firmware< 2020-07-10
LenovoThinkpad A475 Firmware< 2020-07-10
LenovoThinkpad A485 Firmware< 2020-07-10
LenovoThinkpad E14 Firmware< 2020-07-10
LenovoThinkpad E15 Firmware< 2020-07-10
LenovoThinkpad R14 Firmware< 2020-07-10
LenovoThinkpad S3 Gen 2 Firmware< 2020-07-10
LenovoThinkpad E455 Firmware< 2020-07-10
LenovoThinkpad E555 Firmware< 2020-07-10
LenovoThinkpad E460 Firmware< 2020-07-10
LenovoThinkpad E560 Firmware< 2020-07-10
LenovoThinkpad E465 Firmware< 2020-07-10
LenovoThinkpad E565 Firmware< 2020-07-10
LenovoThinkpad E470 Firmware< 2020-07-10
LenovoThinkpad E570 Firmware< 2020-07-10
LenovoThinkpad E475 Firmware< 2020-07-10
LenovoThinkpad E575 Firmware< 2020-07-10
LenovoThinkpad E480 Firmware< 2020-07-10
LenovoThinkpad E580 Firmware< 2020-07-10
LenovoThinkpad E485 Firmware< 2020-07-10
LenovoThinkpad E585 Firmware< 2020-07-10
LenovoThinkpad E490s Firmware< 2020-07-10
LenovoThinkpad S3 Firmware< 2020-07-10
LenovoThinkpad E490 Firmware< 2020-07-10
LenovoThinkpad E590 Firmware< 2020-07-10
LenovoThinkpad R490 Firmware< 2020-07-10
LenovoThinkpad R590 Firmware< 2020-07-10
LenovoThinkpad L13 Firmware< 2020-07-10
LenovoThinkpad L1415 Firmware< 2020-07-10
LenovoThinkpad L380 Firmware< 2020-07-10
LenovoThinkpad S3 3rd Gen Firmware< 2020-07-10
LenovoThinkpad L380 Yoga Firmware< 2020-07-10
LenovoThinkpad S2 Yoga 3rd Gen Firmware< 2020-07-10
LenovoThinkpad L390 Yoga Firmware< 2020-07-10
LenovoThinkpad S2 Yoga 4th Gen Firmware< 2020-07-10
LenovoThinkpad L460 Firmware< 2020-07-10
LenovoThinkpad L470 Firmware< 2020-07-10
LenovoThinkpad L480 Firmware< 2020-07-10
LenovoThinkpad L580 Firmware< 2020-07-10
LenovoThinkpad L490 Firmware< 2020-07-10
LenovoThinkpad L590 Firmware< 2020-07-10
LenovoThinkpad L560 Firmware< 2020-07-03

Showing 50 of 100 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-8320?
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
How severe is CVE-2020-8320?
CVE-2020-8320 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.27% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8320?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-8320?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST