Vulnerability Description
The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer RQ940, RS140, TS140, TS240, TS440, and TS540 devices; and ThinkStation E32, P300, and P310 devices might allow local users or physically proximate attackers to bypass the Secure Boot protection mechanism by leveraging an AMI test key.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Bios | - |
| Lenovo | Thinkcentre E93 | - |
| Lenovo | Thinkcentre M6500T\/S | - |
| Lenovo | Thinkcentre M6600 | - |
| Lenovo | Thinkcentre M6600Q | - |
| Lenovo | Thinkcentre M6600T\/S | - |
| Lenovo | Thinkcentre M73P | - |
| Lenovo | Thinkcentre M800 | - |
| Lenovo | Thinkcentre M83 | - |
| Lenovo | Thinkcentre M8500T\/S | - |
| Lenovo | Thinkcentre M8600T\/S | - |
| Lenovo | Thinkcentre M900 | - |
| Lenovo | Thinkcentre M93 | - |
| Lenovo | Thinkcentre M93P | - |
| Lenovo | Thinkserver Rq940 | - |
| Lenovo | Thinkserver Rs140 | - |
| Lenovo | Thinkserver Ts140 | - |
| Lenovo | Thinkserver Ts240 | - |
| Lenovo | Thinkserver Ts440 | - |
| Lenovo | Thinkserver Ts540 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/92661Third Party Advisory
- https://support.lenovo.com/product_security/PS500067MitigationVendor Advisory
- http://www.securityfocus.com/bid/92661Third Party Advisory
- https://support.lenovo.com/product_security/PS500067MitigationVendor Advisory
FAQ
What is CVE-2016-5247?
CVE-2016-5247 is a vulnerability with a CVSS score of 7.8 (HIGH). The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer RQ940, RS140, TS140, TS240, TS440, and TS540 devic...
How severe is CVE-2016-5247?
CVE-2016-5247 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5247?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Bios, Lenovo Thinkcentre E93, Lenovo Thinkcentre M6500T\/S, Lenovo Thinkcentre M6600, Lenovo Thinkcentre M6600Q.