MEDIUM · 6.4

CVE-2020-8320

An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

Vulnerability Description

An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

CVSS Score

6.4

MEDIUM

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoThinkpad 11E Yoga Gen 6 Firmware< 2020-07-10
LenovoThinkpad 11E Yoga Gen 6-
LenovoThinkpad 11E Firmware< 2020-07-10
LenovoThinkpad 11E-
LenovoThinkpad Yoga 11E 3Rd Gen Firmware< 2020-07-10
LenovoThinkpad Yoga 11E 3Rd Gen-
LenovoThinkpad Yoga 11E 4Th Gen Firmware< 2020-07-10
LenovoThinkpad Yoga 11E 4Th Gen-
LenovoThinkpad Yoga 11E 5Th Gen Firmware< 2020-07-10
LenovoThinkpad Yoga 11E 5Th Gen-
LenovoThinkpad 13 2Nd Gen Firmware< 2020-07-10
LenovoThinkpad 13 2Nd Gen-
LenovoThinkpad 13 Firmware< 2020-07-10
LenovoThinkpad 13-
LenovoThinkpad A275 Firmware< 2020-07-10
LenovoThinkpad A275-
LenovoThinkpad A285 Firmware< 2020-07-10
LenovoThinkpad A285-
LenovoThinkpad A475 Firmware< 2020-07-10
LenovoThinkpad A475-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-8320?

CVE-2020-8320 is a vulnerability with a CVSS score of 6.4 (MEDIUM). An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

How severe is CVE-2020-8320?

CVE-2020-8320 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8320?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkpad 11E Yoga Gen 6 Firmware, Lenovo Thinkpad 11E Yoga Gen 6, Lenovo Thinkpad 11E Firmware, Lenovo Thinkpad 11E, Lenovo Thinkpad Yoga 11E 3Rd Gen Firmware.