Vulnerability Description
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkpad 11E Yoga Gen 6 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad 11E Yoga Gen 6 | - |
| Lenovo | Thinkpad 11E Firmware | < 2020-07-10 |
| Lenovo | Thinkpad 11E | - |
| Lenovo | Thinkpad Yoga 11E 3Rd Gen Firmware | < 2020-07-10 |
| Lenovo | Thinkpad Yoga 11E 3Rd Gen | - |
| Lenovo | Thinkpad Yoga 11E 4Th Gen Firmware | < 2020-07-10 |
| Lenovo | Thinkpad Yoga 11E 4Th Gen | - |
| Lenovo | Thinkpad Yoga 11E 5Th Gen Firmware | < 2020-07-10 |
| Lenovo | Thinkpad Yoga 11E 5Th Gen | - |
| Lenovo | Thinkpad 13 2Nd Gen Firmware | < 2020-07-10 |
| Lenovo | Thinkpad 13 2Nd Gen | - |
| Lenovo | Thinkpad 13 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad 13 | - |
| Lenovo | Thinkpad A275 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad A275 | - |
| Lenovo | Thinkpad A285 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad A285 | - |
| Lenovo | Thinkpad A475 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad A475 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
FAQ
What is CVE-2020-8320?
CVE-2020-8320 is a vulnerability with a CVSS score of 6.4 (MEDIUM). An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
How severe is CVE-2020-8320?
CVE-2020-8320 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8320?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkpad 11E Yoga Gen 6 Firmware, Lenovo Thinkpad 11E Yoga Gen 6, Lenovo Thinkpad 11E Firmware, Lenovo Thinkpad 11E, Lenovo Thinkpad Yoga 11E 3Rd Gen Firmware.