Vulnerability Description
A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | 20F1 Firmware | - |
| Lenovo | 20F1 | - |
| Lenovo | 20F2 Firmware | - |
| Lenovo | 20F2 | - |
| Lenovo | 20Jq Firmware | - |
| Lenovo | 20Jq | - |
| Lenovo | 20Jr Firmware | - |
| Lenovo | 20Jr | - |
| Lenovo | 20G9 Firmware | - |
| Lenovo | 20G9 | - |
| Lenovo | 20Gb Firmware | - |
| Lenovo | 20Gb | - |
| Lenovo | 20G8 Firmware | - |
| Lenovo | 20G8 | - |
| Lenovo | 20Ga Firmware | - |
| Lenovo | 20Ga | - |
| Lenovo | 20Ht Firmware | - |
| Lenovo | 20Ht | - |
| Lenovo | 20Hv Firmware | - |
| Lenovo | 20Hv | - |
References
- https://support.lenovo.com/solutions/LEN-27764Vendor Advisory
- https://support.lenovo.com/solutions/LEN-27764Vendor Advisory
FAQ
What is CVE-2019-6171?
CVE-2019-6171 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller ...
How severe is CVE-2019-6171?
CVE-2019-6171 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6171?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo 20F1 Firmware, Lenovo 20F1, Lenovo 20F2 Firmware, Lenovo 20F2, Lenovo 20Jq Firmware.