CVE-2021-3970
Last modified
CVE-2021-3970 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.
Description
A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Ideapad 3-14ada05 Firmware | < e8cn33ww |
| Lenovo | Ideapad 3-14ada6 Firmware | < hbcn21ww |
| Lenovo | Ideapad 3-14alc6 Firmware | < glcn43ww |
| Lenovo | Ideapad 3-14are05 Firmware | < dzcn42ww |
| Lenovo | Ideapad 3-15ada6 Firmware | < hbcn21ww |
| Lenovo | Ideapad 3-15alc6 Firmware | < glcn43ww |
| Lenovo | Ideapad 3-15are05 Firmware | < dzcn42ww |
| Lenovo | Ideapad 3-15igl05 Firmware | < dvcn23ww |
| Lenovo | Ideapad 3-17ada05 Firmware | < e8cn33ww |
| Lenovo | Ideapad 3-17ada6 Firmware | < hbcn21ww |
| Lenovo | Ideapad 3-17alc6 Firmware | < glcn43ww |
| Lenovo | Ideapad 3-17are05 Firmware | < dzcn42ww |
| Lenovo | Ideapad 3-17iil05 Firmware | < emcn52ww |
| Lenovo | Ideapad 3-17itl6 Firmware | < ggcn33ww |
| Lenovo | Ideapad 3-15ada05 Firmware | < e8cn33ww |
| Lenovo | L3 15iml05 Firmware | < ejcn27ww |
| Lenovo | L3-15itl6 Firmware | < gfcn23ww |
| Lenovo | L340-15irh Firmware | < bgcn35ww |
| Lenovo | L340-15iwl Firmware | < atcn46ww |
| Lenovo | L340-15iwl Touch Firmware | < atcn46ww |
| Lenovo | L340-17irh Firmware | < bgcn35ww |
| Lenovo | L340-17iwl Firmware | < atcn46ww |
| Lenovo | Legion 5 Pro-16ach6 Firmware | < hhcn25ww |
| Lenovo | Legion 5 Pro-16ach6h Firmware | < gkcn51ww |
| Lenovo | Legion 5 Pro-16ith6 Firmware | < h1cn46ww |
| Lenovo | Legion 5 Pro-16ith6h Firmware | < h1cn46ww |
| Lenovo | Legion 5-15ach6 Firmware | < hhcn25ww |
| Lenovo | Legion 5-15ach6a Firmware | < g9cn28ww |
| Lenovo | Legion 5-15ach6h Firmware | < gkcn51ww |
| Lenovo | Legion 5-15imh6 Firmware | < g8cn19ww |
| Lenovo | Legion 5-15ith6 Firmware | < h1cn46ww |
| Lenovo | Legion 5-15ith6h Firmware | < h1cn46ww |
| Lenovo | Legion 5-17ach6 Firmware | < hhcn25ww |
| Lenovo | Legion 5-17ach6h Firmware | < gkcn51ww |
| Lenovo | Legion 5-17ith6 Firmware | < h1cn46ww |
| Lenovo | Legion 5-17ith6h Firmware | < h1cn46ww |
| Lenovo | Legion 7-16achg6 Firmware | < gkcn51ww |
| Lenovo | Legion 7-16ithg6 Firmware | < gkcn51ww |
| Lenovo | Legion S7-15ach6 Firmware | < hacn35ww |
| Lenovo | Legion Y540-15irh Firmware | < bhcn44ww |
| Lenovo | Legion Y540-15irh-Pg0 Firmware | < bhcn44ww |
| Lenovo | Legion Y540-17irh Firmware | < bhcn44ww |
| Lenovo | Legion Y540-17irh-Pg0 Firmware | < bhcn44ww |
| Lenovo | Legion Y545 Firmware | < bhcn44ww |
| Lenovo | Legion Y545-Pg0 Firmware | < bhcn44ww |
| Lenovo | Legion Y7000-2019 Firmware | < bhcn44ww |
| Lenovo | Legion Y7000-2019-Pg0 Firmware | < bhcn44ww |
| Lenovo | S14 G2 Itl Firmware | < ggcn33ww |
| Lenovo | S145-14api Firmware | < bucn31ww |
| Lenovo | S145-14ast Firmware | < aycn26ww |
Showing 50 of 105 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/us/en/product_security/LEN-73440Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-73440Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3970?
How severe is CVE-2021-3970?
How do I fix CVE-2021-3970?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-39693In onUidStateChanged of AppOpsService.java, there is a possi…7.8
- CVE-2021-39694In parse of RoleParser.java, there is a possible way for def…7.8
- CVE-2021-39695In createOrUpdate of BasePermission.java, there is a possibl…7.8
- CVE-2021-39696In Task.java, there is a possible escalation of privilege du…7.8
- CVE-2021-39697In checkFileUriDestination of DownloadProvider.java, there i…7.8
- CVE-2021-39698In aio_poll_complete_work of aio.c, there is a possible memo…7.8
- CVE-2021-39700In the policies of adbd.te, there was a logic error which ca…5.5
- CVE-2021-39701In serviceConnection of ControlsProviderLifecycleManager.kt,…7.8
- CVE-2021-39702In onCreate of RequestManageCredentials.java, there is a pos…7.8
- CVE-2021-39703In updateState of UsbDeviceManager.java, there is a possible…7.8
- CVE-2021-39704In deleteNotificationChannelGroup of NotificationManagerServ…7.8
- CVE-2021-39705Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2021-3970?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
