MEDIUM · 5.9

CVE-2018-9069

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator ac...

Vulnerability Description

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Hp310S-14Isk Firmware< 1.15
Hp310S-14Isk-
Hp320-15Ikbra Firmware< 6jcn24ww
Hp320-15Ikbra-
Hp320-15Ikbrn Firmware< 6jcn24ww
Hp320-15Ikbrn-
Hp320-15Ikbrn Touch Firmware< 6jcn24ww
Hp320-15Ikbrn Touch-
Hp320-17Ikbrn< 2.09
Hp320S-14Ikb< 2.09
Hp320S-15Ikb Firmware< 2.09
Hp320S-15Ikb-
Hp320S-15Isk Firmware< 2wcn38ww
Hp320S-15Isk-
Hp510S-14Isk Firmware< 1.15
Hp510S-14Isk-
Hp520-15Ikbrn Firmware< 6jcn26ww
Hp520-15Ikbrn-
Hp520S-14Ikb Firmware< 2.09
Hp520S-14Ikb-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-9069?

CVE-2018-9069 is a vulnerability with a CVSS score of 5.9 (MEDIUM). In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator ac...

How severe is CVE-2018-9069?

CVE-2018-9069 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-9069?

Check the references section above for vendor advisories and patch information. Affected products include: Hp 310S-14Isk Firmware, Hp 310S-14Isk, Hp 320-15Ikbra Firmware, Hp 320-15Ikbra, Hp 320-15Ikbrn Firmware.