CVE-2020-8320
MEDIUMCVSS 6.8/10EPSS 0.27%
Last modified
CVE-2020-8320 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkpad 11e Yoga Gen 6 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad 11e Firmware | < 2020-07-10 |
| Lenovo | Thinkpad Yoga 11e 3rd Gen Firmware | < 2020-07-10 |
| Lenovo | Thinkpad Yoga 11e 4th Gen Firmware | < 2020-07-10 |
| Lenovo | Thinkpad Yoga 11e 5th Gen Firmware | < 2020-07-10 |
| Lenovo | Thinkpad 13 2nd Gen Firmware | < 2020-07-10 |
| Lenovo | Thinkpad 13 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad A275 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad A285 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad A475 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad A485 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E14 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E15 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad R14 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad S3 Gen 2 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E455 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E555 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E460 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E560 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E465 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E565 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E470 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E570 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E475 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E575 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E480 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E580 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E485 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E585 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E490s Firmware | < 2020-07-10 |
| Lenovo | Thinkpad S3 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E490 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E590 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad R490 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad R590 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L13 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L1415 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L380 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad S3 3rd Gen Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L380 Yoga Firmware | < 2020-07-10 |
| Lenovo | Thinkpad S2 Yoga 3rd Gen Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L390 Yoga Firmware | < 2020-07-10 |
| Lenovo | Thinkpad S2 Yoga 4th Gen Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L460 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L470 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L480 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L580 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L490 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L590 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad L560 Firmware | < 2020-07-03 |
Showing 50 of 100 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8320?
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
How severe is CVE-2020-8320?
CVE-2020-8320 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.27% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8320?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8300Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 1…6.5
- CVE-2020-8315In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, a…5.5
- CVE-2020-8316A vulnerability was reported in Lenovo Vantage prior to vers…4.4
- CVE-2020-8317A DLL search path vulnerability was reported in Lenovo Drive…7.8
- CVE-2020-8318A privilege escalation vulnerability was reported in the Len…7.8
- CVE-2020-8319A privilege escalation vulnerability was reported in Lenovo …7.8
- CVE-2020-8321A potential vulnerability in the SMI callback function used …6.7
- CVE-2020-8322A potential vulnerability in the SMI callback function used …6.7
- CVE-2020-8323A potential vulnerability in the SMI callback function used …6.7
- CVE-2020-8324A vulnerability was reported in LenovoAppScenarioPluginSyste…5.5
- CVE-2020-8325Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-8326An unquoted service path vulnerability was reported in Lenov…7.8
Are you affected by CVE-2020-8320?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
