CVE-2021-3453

MEDIUMCVSS 4.6/10EPSS 0.24%

Last modified

CVE-2021-3453 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.

Description

Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

Metrics

CVSS 3.1
4.6/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
0.24%

14.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoThinkpad Helix Firmwaren17etb4w
LenovoThinkpad T550 Firmwaren11et53w
LenovoThinkpad W550s Firmwaren11et53w
LenovoThinkpad X1 Carbon 3rd Gen Firmwaren14et55w
LenovoThinkpad X250 Firmwaren10et62w
LenovoThinkpad Yoga 15 Firmwaren19et65w
Lenovo730s-13iml FirmwareAll versions
LenovoIdeapad 1-11igl05 FirmwareAll versions
LenovoIdeapad 1-14igl05 FirmwareAll versions
LenovoIdeapad S940-14iil FirmwareAll versions
LenovoIdeapad S940-14iwl FirmwareAll versions
LenovoIdeapad Slim 1-11ast-05 FirmwareAll versions
LenovoIdeapad Slim 1-14ast-05 FirmwareAll versions
LenovoV130-15igm FirmwareAll versions
LenovoV330-15ikb FirmwareAll versions
LenovoV330-15isk FirmwareAll versions
LenovoYoga S730-13iml FirmwareAll versions
LenovoYoga S940-14iil FirmwareAll versions
LenovoYoga S940-14iwl FirmwareAll versions
LenovoIdeacentre Aio 5-24imb05 Firmware< 2021-09-30
LenovoIdeacentre Aio 5-74imb05 Firmware< 2021-09-30

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-3453?
Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
How severe is CVE-2021-3453?
CVE-2021-3453 has a CVSS score of 4.6/10 (MEDIUM severity). The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2021-3453?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-3453?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST