Vulnerability Description
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkpad T490 \(20Nx\) Firmware | < n2iet90w |
| Lenovo | Thinkpad T490 \(20Nx\) | - |
| Lenovo | Thinkpad T490 \(20Qx\) Firmware | < n2iet90w |
| Lenovo | Thinkpad T490 \(20Qx\) | - |
| Lenovo | Thinkpad T490 \(20Rx\) Firmware | < n2ret16w |
| Lenovo | Thinkpad T490 \(20Rx\) | - |
| Lenovo | Thinkpad T490S \(20Nx\) Firmware | < n2jet89w |
| Lenovo | Thinkpad T490S \(20Nx\) | - |
| Lenovo | Thinkpad T495 Drift Firmware | < 2020-08-30 |
| Lenovo | Thinkpad T495 Drift | - |
| Lenovo | Thinkpad T590 \(20Nx\) Firmware | < n2iet90w |
| Lenovo | Thinkpad T590 \(20Nx\) | - |
| Lenovo | Thinkpad X1 Carbon \(20Qx\) Firmware | < n2het54w |
| Lenovo | Thinkpad X1 Carbon \(20Qx\) | - |
| Lenovo | Thinkpad X1 Yoga \(20Qx\) Firmware | < n2het54w |
| Lenovo | Thinkpad X1 Yoga \(20Qx\) | - |
| Lenovo | Thinkpad X390 \(20Qx\) Firmware | < n2jet89w |
| Lenovo | Thinkpad X390 \(20Qx\) | - |
| Lenovo | Thinkpad X390 \(20Sx\) Firmware | < n2set18w |
| Lenovo | Thinkpad X390 \(20Sx\) | - |
References
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
FAQ
What is CVE-2020-8341?
CVE-2020-8341 is a vulnerability with a CVSS score of 2.4 (LOW). In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Reg...
How severe is CVE-2020-8341?
CVE-2020-8341 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8341?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkpad T490 \(20Nx\) Firmware, Lenovo Thinkpad T490 \(20Nx\), Lenovo Thinkpad T490 \(20Qx\) Firmware, Lenovo Thinkpad T490 \(20Qx\), Lenovo Thinkpad T490 \(20Rx\) Firmware.