MEDIUM · 6.1

CVE-2020-8335

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS ver...

Vulnerability Description

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoThinkpad A275 Firmware< 2020-08-30
LenovoThinkpad A275-
LenovoThinkpad A285 Firmware< 2020-08-30
LenovoThinkpad A285-
LenovoThinkpad A475 Firmware< 2020-08-30
LenovoThinkpad A475-
LenovoThinkpad A485 Firmware< 2020-08-30
LenovoThinkpad A485-
LenovoThinkpad T495 Drift Firmware< 2020-08-30
LenovoThinkpad T495 Drift-
LenovoThinkpad T495S Jazz Firmware< 2020-08-30
LenovoThinkpad T495S Jazz-
LenovoThinkpad X1 Carbon \(20Bx\) Firmware< n14et54w
LenovoThinkpad X1 Carbon \(20Bx\)-
LenovoThinkpad X395 Firmware< 2020-08-30
LenovoThinkpad X395-

References

FAQ

What is CVE-2020-8335?

CVE-2020-8335 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS ver...

How severe is CVE-2020-8335?

CVE-2020-8335 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8335?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkpad A275 Firmware, Lenovo Thinkpad A275, Lenovo Thinkpad A285 Firmware, Lenovo Thinkpad A285, Lenovo Thinkpad A475 Firmware.