PT-2022-2319 · Lenovo · Lenovo Notebook

Published

2022-04-18

·

Updated

2022-05-06

·

CVE-2021-3971

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lenovo Notebook devices (affected versions not specified)
Description A potential issue in the BIOS of some Lenovo Notebook devices could allow an attacker with elevated privileges to modify the firmware protection region by changing an NVRAM variable, potentially enabling the placement of malicious code in the SPI flash memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02509
CVE-2021-3971

Affected Products

Lenovo Notebook