Vulnerability Description
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkcentre E93 Firmware | < fbktdba |
| Lenovo | Thinkcentre E93 | - |
| Lenovo | Thinkcentre M6500S Firmware | < fbktdba |
| Lenovo | Thinkcentre M6500S | - |
| Lenovo | Thinkcentre M6500T Firmware | < fbktdba |
| Lenovo | Thinkcentre M6500T | - |
| Lenovo | Thinkcentre M73P Firmware | < fbktdba |
| Lenovo | Thinkcentre M73P | - |
| Lenovo | Thinkcentre M83 Firmware | < fbktdba |
| Lenovo | Thinkcentre M83 | - |
| Lenovo | Thinkcentre M8500S Firmware | < fbktdba |
| Lenovo | Thinkcentre M8500S | - |
| Lenovo | Thinkcentre M8500T Firmware | < fbktdba |
| Lenovo | Thinkcentre M8500T | - |
| Lenovo | Thinkcentre M93 Firmware | < fbktdba |
| Lenovo | Thinkcentre M93 | - |
| Lenovo | Thinkcentre M93P Firmware | < fbktdba |
| Lenovo | Thinkcentre M93P | - |
| Lenovo | Thinkstation E32 Firmware | < fbktdba |
| Lenovo | Thinkstation E32 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-28078Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/176178Third Party AdvisoryVDB Entry
- https://support.lenovo.com/us/en/product_security/LEN-28078Vendor Advisory
FAQ
What is CVE-2019-6190?
CVE-2019-6190 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared i...
How severe is CVE-2019-6190?
CVE-2019-6190 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6190?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkcentre E93 Firmware, Lenovo Thinkcentre E93, Lenovo Thinkcentre M6500S Firmware, Lenovo Thinkcentre M6500S, Lenovo Thinkcentre M6500T Firmware.