MEDIUM · 6.7

CVE-2017-3754

Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to ...

Vulnerability Description

Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.

CVSS Score

6.7

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoBios-
Lenovo710S-13Ikb\/Xiaoxin Air 13Ikb-
Lenovo710S-13Isk\/Xiaoxin Air 13-
LenovoK21-80-
LenovoK22-80\/Lenovo V720-12-
LenovoK41-80-
LenovoLenovo Ideapad 110-14Ast-
LenovoLenovo Ideapad 110-15Ast-
LenovoLenovo Ideapad 320-14Ast-
LenovoLenovo Ideapad 320-15Ast-
LenovoLenovo Xiaoxin Rui7000-
LenovoMiix 710-12Ikb-
LenovoMiix 720-12Ikb-
LenovoNotebook 320-17Ast-
LenovoRescuer E520-15Ikb-
LenovoV110-14Iap-
LenovoV110-15Iap-
LenovoV110-15Ikb-
LenovoV110-15Isk-
LenovoYoga 710-11Ikb-

References

FAQ

What is CVE-2017-3754?

CVE-2017-3754 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to ...

How severe is CVE-2017-3754?

CVE-2017-3754 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-3754?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Bios, Lenovo 710S-13Ikb\/Xiaoxin Air 13Ikb, Lenovo 710S-13Isk\/Xiaoxin Air 13, Lenovo K21-80, Lenovo K22-80\/Lenovo V720-12.