CVE-2021-3718

MEDIUMCVSS 4.6/10EPSS 0.21%

Last modified

CVE-2021-3718 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS.

Metrics

CVSS 3.1
4.6/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.21%

11.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoThinkpad 11e 3rd Gen Firmware<= 1.22
LenovoThinkpad 11e 3rd Gen Firmware<= 1.29
LenovoThinkpad 11e 4th Gen I3 Firmware<= 1.22
LenovoThinkpad 11e 4th Gen I7 Firmware<= 1.22
LenovoThinkpad 11e 4th Gen I5 Firmware<= 1.22
LenovoThinkpad 11e 4th Gen Celeron Firmware<= 1.27
LenovoThinkpad 11e Yoga Gen 6 Firmware<= 1.12
LenovoThinkpad 13 Gen 2 Firmware<= 1.29
LenovoThinkpad E490 Firmware<= 1.30
LenovoThinkpad E490s Firmware<= 1.30
LenovoThinkpad E590 Firmware<= 1.30
LenovoThinkpad L13 Firmware<= 1.31
LenovoThinkpad L13 Gen 2 Firmware<= 1.11
LenovoThinkpad L13 Gen 2 Firmware<= 1.08
LenovoThinkpad L13 Yoga Firmware<= 1.31
LenovoThinkpad L13 Yoga Gen 2 Firmware<= 1.11
LenovoThinkpad L13 Yoga Gen 2 Firmware<= 1.08
LenovoThinkpad L14 Gen 1 Firmware< 1.15
LenovoThinkpad L14 Firmware< 1.20.1.17
LenovoThinkpad L15 Gen 1 Firmware< 1.15
LenovoThinkpad L15 Firmware< 1.20.1.17
LenovoThinkpad L380 Firmware<= 1.26
LenovoThinkpad L380 Yoga Firmware<= 1.26
LenovoThinkpad L390 Yoga Firmware<= 1.35
LenovoThinkpad L390 Firmware<= 1.35
LenovoThinkpad L490 Firmware< 1.26
LenovoThinkpad L590 Firmware< 1.26
LenovoThinkpad P43s Firmware< n2iet96w
LenovoThinkpad P52 Firmware< n2cet60w
LenovoThinkpad P53s Firmware< n2iet96w
LenovoThinkpad P72 Firmware< n2cet60w
LenovoThinkpad S5 2nd Gen Firmware<= 1.28
LenovoThinkpad T460 Firmware<= 1.43.1.11
LenovoThinkpad T490 Firmware< n2iet96w
LenovoThinkpad T590 Firmware< n2iet96w
LenovoThinkpad S2 Gen 6 Firmware<= 2021-09-30
LenovoThinkpad S2 Yoga Gen 6 Firmware<= 2021-09-30
LenovoThinkpad X12 Detachable Gen 1 Firmware< 1.16
LenovoThinkpad X260 Firmware<= 1.47\/1.15
LenovoThinkpad X380 Yoga Firmware<= 1.34
LenovoThinkpad X390 Yoga Firmware< n2let87w
LenovoThinkpad 11e 5th Gen Firmware<= 1.13

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-3718?
A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS.
How severe is CVE-2021-3718?
CVE-2021-3718 has a CVSS score of 4.6/10 (MEDIUM severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2021-3718?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-3718?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST