CVE-2021-3599
Last modified
CVE-2021-3599 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkpad X380 Yoga Firmware | < 2020-10-31 |
| Lenovo | Thinkpad X1 Fold Gen 1 Firmware | < 2021-10-29 |
| Lenovo | Thinkpad Yoga 260 Firmware | < 2021-10-25 |
| Lenovo | Thinkpad Yoga 11e 3rd Gen Firmware | < 2021-10-31 |
| Lenovo | Thinkpad Yoga 15 Firmware | < n19et66w |
| Lenovo | Thinkpad Yoga 370 Firmware | < 2021-10-31 |
| Lenovo | Thinkpad X12 Detachable Gen 1 Firmware | < 2021-10-31 |
| Lenovo | Thinkpad X390 Firmware | < n2jet96w |
| Lenovo | Thinkpad Yoga 11e 4th Gen Firmware | < 2021-10-31 |
| Lenovo | Thinkpad Yoga 11e 5th Gen Firmware | < 2021-10-31 |
| Lenovo | Thinkpad X250 Firmware | < 2021-10-31 |
| Lenovo | Thinkpad X260 Firmware | < 2021-10-31 |
| Lenovo | Thinkpad X390 Yoga Firmware | < n2let87w |
| Lenovo | Thinkpad X280 Firmware | < n20et58w |
| Lenovo | Thinkpad X1 Titanium Firmware | < n2met51w |
| Lenovo | Thinkpad X270 Firmware | < 2021-10-29 |
| Lenovo | Thinkpad X1 Carbon 5th Gen Kabylake Firmware | < n1met66w |
| Lenovo | Thinkpad X13 Gen 1 Firmware | < n2yet31w |
| Lenovo | Thinkpad X13 Gen 2 Firmware | < n35et41w |
| Lenovo | Thinkpad X13 Yoga Gen 1 Firmware | < n2uet56w |
| Lenovo | Thinkpad X13 Yoga Gen 2 Firmware | < n39et47w |
| Lenovo | Thinkpad X1 Carbon 5th Gen Skylake Firmware | < n1met66w |
| Lenovo | Thinkpad X1 Yoga 1st Gen Firmware | < n1fet76w |
| Lenovo | Thinkpad X1 Yoga 3rd Gen Firmware | < n25et57w |
| Lenovo | Thinkpad X1 Yoga 4th Gen Firmware | < n2het64w |
| Lenovo | Thinkpad X1 Yoga Gen 5 Firmware | < n2wet30w |
| Lenovo | Thinkpad X1 Carbon 4th Gen Firmware | < n1fet76w |
| Lenovo | Thinkpad 10 Firmware | < 2021-10-25 |
| Lenovo | Thinkpad X1 Nano Gen 1 Firmware | < n2tet67w |
| Lenovo | Thinkpad X1 Extreme Firmware | < n2eet54w |
| Lenovo | Thinkpad X1 Extreme 2nd Firmware | < n2oet53w |
| Lenovo | Thinkpad X1 Extreme Gen 3 Firmware | < n2vet33w |
| Lenovo | Thinkpad T460s Firmware | < n1cet84w |
| Lenovo | Thinkpad S2 Gen 6 Firmware | < 2021-10-31 |
| Lenovo | Thinkpad X1 Carbon Gen 6 Firmware | < n23et78w |
| Lenovo | Thinkpad X1 Carbon Gen 7 Firmware | < n2het64w |
| Lenovo | Thinkpad X1 Carbon Gen 8 Firmware | < n2het64w |
| Lenovo | Thinkpad T560 Firmware | < n1ket52w |
| Lenovo | Thinkpad T460p Firmware | < 2021-10-29 |
| Lenovo | Thinkpad W550s Firmware | < n11et54w |
| Lenovo | Thinkpad T590 Firmware | < n2iet96w |
| Lenovo | Thinkpad T570 Firmware | < n1vet57w |
| Lenovo | Thinkpad S2 Yoga Gen 6 Firmware | < 2021-10-31 |
| Lenovo | Thinkpad T480 Firmware | < n24et65w |
| Lenovo | Thinkpad X1 Tablet Firmware | < n1let92w |
| Lenovo | Thinkpad T550 Firmware | < n11et54w |
| Lenovo | Thinkpad X1 Carbon 3rd Gen Firmware | < n14et56w |
| Lenovo | Thinkpad X1 Tablet Gen 2 Firmware | < n1oet56w |
| Lenovo | Thinkpad X1 Tablet Gen 3 Firmware | < 2021-10-29 |
| Lenovo | Thinkpad T580 Firmware | < n27et43w |
Showing 50 of 136 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/us/en/product_security/LEN-67440Patch, Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-67440Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3599?
How severe is CVE-2021-3599?
How do I fix CVE-2021-3599?
Are you affected by CVE-2021-3599?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
