CVE-2020-8341
Last modified
CVE-2020-8341 is a low-severity vulnerability rated 2.4/10 on the CVSS scale. In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkpad T490 \(20nx\) Firmware | < n2iet90w |
| Lenovo | Thinkpad T490 \(20qx\) Firmware | < n2iet90w |
| Lenovo | Thinkpad T490 \(20rx\) Firmware | < n2ret16w |
| Lenovo | Thinkpad T490s \(20nx\) Firmware | < n2jet89w |
| Lenovo | Thinkpad T495 Drift Firmware | < 2020-08-30 |
| Lenovo | Thinkpad T590 \(20nx\) Firmware | < n2iet90w |
| Lenovo | Thinkpad X1 Carbon \(20qx\) Firmware | < n2het54w |
| Lenovo | Thinkpad X1 Yoga \(20qx\) Firmware | < n2het54w |
| Lenovo | Thinkpad X390 \(20qx\) Firmware | < n2jet89w |
| Lenovo | Thinkpad X390 \(20sx\) Firmware | < n2set18w |
References
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8341?
How severe is CVE-2020-8341?
How do I fix CVE-2020-8341?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8335The BIOS tamper detection mechanism was not triggered in Len…6.8
- CVE-2020-8336Lenovo implemented Intel CSME Anti-rollback ARB protections …6.8
- CVE-2020-8337An unquoted search path vulnerability was reported in versio…6.7
- CVE-2020-8338A DLL search path vulnerability was reported in Lenovo Diagn…7.8
- CVE-2020-8339A cross-site scripting inclusion (XSSI) vulnerability was re…6.1
- CVE-2020-8340A cross-site scripting (XSS) vulnerability was discovered in…6.1
- CVE-2020-8342A race condition vulnerability was reported in Lenovo System…7
- CVE-2020-8343Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-8344Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-8345A DLL search path vulnerability was reported in the Lenovo H…7.8
- CVE-2020-8346A denial of service vulnerability was reported in the Lenovo…5.5
- CVE-2020-8347A reflective cross-site scripting (XSS) vulnerability was re…6.1
Are you affected by CVE-2020-8341?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
