Description
A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain conditions during a BIOS update performed by Lenovo Vantage.
Published: 2021-07-16
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-65529.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-26918 A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain conditions during a BIOS update performed by Lenovo Vantage.
History

No history.

Subscriptions

Lenovo 100e 2nd Gen 100e 2nd Gen Firmware 300e 2nd Gen 300e 2nd Gen Firmware Ideapad 1-11ada05 Ideapad 1-11ada05 Firmware Ideapad 1-11igl05 Ideapad 1-11igl05 Firmware Ideapad 1-14ada05 Ideapad 1-14ada05 Firmware Ideapad 1-14igl05 Ideapad 1-14igl05 Firmware Ideapad 730-13iml Ideapad 730-13iml Firmware Ideapad Flex 5-14alc05 Ideapad Flex 5-14alc05 Firmware Ideapad Flex 5-15alc05 Ideapad Flex 5-15alc05 Firmware Ideapad S940-14iil Ideapad S940-14iil Firmware Ideapad S940-14iwl Ideapad S940-14iwl Firmware Ideapad Slim 1-11ast-05 Ideapad Slim 1-11ast-05 Firmware Ideapad Slim 1-14ast-05 Ideapad Slim 1-14ast-05 Firmware Ideapad Yoga C940-15irh Ideapad Yoga C940-15irh Firmware Ideapad Yoga S730-13iml Ideapad Yoga S730-13iml Firmware Ideapad Yoga S940-14iil Ideapad Yoga S940-14iil Firmware Ideapad Yoga S940-14iwl Ideapad Yoga S940-14iwl Firmware V130-15igm V130-15igm Firmware V130-15ikb V130-15ikb Firmware V330-15ikb V330-15ikb Firmware V330-15isk V330-15isk Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:01:07.203Z

Reserved: 2021-06-23T00:00:00.000Z

Link: CVE-2021-3614

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-07-16T21:15:10.820

Modified: 2024-11-21T06:21:59.070

Link: CVE-2021-3614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses