Vulnerability Description
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkpad E14 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E14 | - |
| Lenovo | Thinkpad E15 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E15 | - |
| Lenovo | Thinkpad R14 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad R14 | - |
| Lenovo | Thinkpad S3 Gen 2 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad S3 Gen 2 | - |
| Lenovo | Thinkpad E490S Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E490S | - |
| Lenovo | Thinkpad S3 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad S3 | - |
| Lenovo | Thinkpad E490 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E490 | - |
| Lenovo | Thinkpad E590 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad E590 | - |
| Lenovo | Thinkpad R490 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad R490 | - |
| Lenovo | Thinkpad R590 Firmware | < 2020-07-10 |
| Lenovo | Thinkpad R590 | - |
References
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
FAQ
What is CVE-2020-8336?
CVE-2020-8336 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.
How severe is CVE-2020-8336?
CVE-2020-8336 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8336?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkpad E14 Firmware, Lenovo Thinkpad E14, Lenovo Thinkpad E15 Firmware, Lenovo Thinkpad E15, Lenovo Thinkpad R14 Firmware.