MEDIUM · 5.0

CVE-2019-6190

Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared i...

Vulnerability Description

Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.

CVSS Score

5.0

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
LenovoThinkcentre E93 Firmware< fbktdba
LenovoThinkcentre E93-
LenovoThinkcentre M6500S Firmware< fbktdba
LenovoThinkcentre M6500S-
LenovoThinkcentre M6500T Firmware< fbktdba
LenovoThinkcentre M6500T-
LenovoThinkcentre M73P Firmware< fbktdba
LenovoThinkcentre M73P-
LenovoThinkcentre M83 Firmware< fbktdba
LenovoThinkcentre M83-
LenovoThinkcentre M8500S Firmware< fbktdba
LenovoThinkcentre M8500S-
LenovoThinkcentre M8500T Firmware< fbktdba
LenovoThinkcentre M8500T-
LenovoThinkcentre M93 Firmware< fbktdba
LenovoThinkcentre M93-
LenovoThinkcentre M93P Firmware< fbktdba
LenovoThinkcentre M93P-
LenovoThinkstation E32 Firmware< fbktdba
LenovoThinkstation E32-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-6190?

CVE-2019-6190 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared i...

How severe is CVE-2019-6190?

CVE-2019-6190 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-6190?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkcentre E93 Firmware, Lenovo Thinkcentre E93, Lenovo Thinkcentre M6500S Firmware, Lenovo Thinkcentre M6500S, Lenovo Thinkcentre M6500T Firmware.