Description
Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.
Published: 2017-07-17
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-12871 Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.
History

No history.

Subscriptions

Lenovo 710s-13ikb\/xiaoxin Air 13ikb 710s-13isk\/xiaoxin Air 13 Bios K21-80 K22-80\/lenovo V720-12 K41-80 Lenovo Ideapad 110-14ast Lenovo Ideapad 110-15ast Lenovo Ideapad 320-14ast Lenovo Ideapad 320-15ast Lenovo Xiaoxin Rui7000 Miix 710-12ikb Miix 720-12ikb Notebook 320-17ast Rescuer E520-15ikb V110-14iap V110-15iap V110-15ikb V110-15isk Yoga 710-11ikb
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-16T18:12:56.349Z

Reserved: 2016-12-16T00:00:00.000Z

Link: CVE-2017-3754

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-07-17T19:29:00.323

Modified: 2026-05-13T00:24:29.033

Link: CVE-2017-3754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses