Vulnerability Description
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | 510-15Ikl Firmware | - |
| Lenovo | 510-15Ikl | - |
| Lenovo | 510S-08Ikl Firmware | - |
| Lenovo | 510S-08Ikl | - |
| Lenovo | Ideacentre 300-20Ish Firmware | - |
| Lenovo | Ideacentre 300-20Ish | - |
| Lenovo | Ideacentre 300S-11Ish Firmware | - |
| Lenovo | Ideacentre 300S-11Ish | - |
| Lenovo | Ideacentre 510-15Icb Firmware | < o3qkt32a |
| Lenovo | Ideacentre 510-15Icb | - |
| Lenovo | Ideacentre 510A-15Icb Firmware | < o3qkt32a |
| Lenovo | Ideacentre 510A-15Icb | - |
| Lenovo | Ideacentre 510S-08Ish Firmware | - |
| Lenovo | Ideacentre 510S-08Ish | - |
| Lenovo | Ideacentre 620S-03Ikl Firmware | - |
| Lenovo | Ideacentre 620S-03Ikl | - |
| Lenovo | Ideacentre 700 Firmware | < fwkt9aa |
| Lenovo | Ideacentre 700 | - |
| Lenovo | Ideacentre 720-18Icb Firmware | < o3qkt32a |
| Lenovo | Ideacentre 720-18Icb | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/solutions/LEN-26332PatchVendor Advisory
- https://support.lenovo.com/solutions/LEN-26332PatchVendor Advisory
FAQ
What is CVE-2019-6156?
CVE-2019-6156 is a vulnerability with a CVSS score of 3.3 (LOW). In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Reg...
How severe is CVE-2019-6156?
CVE-2019-6156 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6156?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo 510-15Ikl Firmware, Lenovo 510-15Ikl, Lenovo 510S-08Ikl Firmware, Lenovo 510S-08Ikl, Lenovo Ideacentre 300-20Ish Firmware.