Vulnerability Description
Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkpad Helix Firmware | n17etb4w |
| Lenovo | Thinkpad Helix | - |
| Lenovo | Thinkpad T550 Firmware | n11et53w |
| Lenovo | Thinkpad T550 | - |
| Lenovo | Thinkpad W550S Firmware | n11et53w |
| Lenovo | Thinkpad W550S | - |
| Lenovo | Thinkpad X1 Carbon 3Rd Gen Firmware | n14et55w |
| Lenovo | Thinkpad X1 Carbon 3Rd Gen | - |
| Lenovo | Thinkpad X250 Firmware | n10et62w |
| Lenovo | Thinkpad X250 | - |
| Lenovo | Thinkpad Yoga 15 Firmware | n19et65w |
| Lenovo | Thinkpad Yoga 15 | - |
| Lenovo | 730S-13Iml Firmware | - |
| Lenovo | 730S-13Iml | - |
| Lenovo | Ideapad 1-11Igl05 Firmware | - |
| Lenovo | Ideapad 1-11Igl05 | - |
| Lenovo | Ideapad 1-14Igl05 Firmware | - |
| Lenovo | Ideapad 1-14Igl05 | - |
| Lenovo | Ideapad S940-14Iil Firmware | - |
| Lenovo | Ideapad S940-14Iil | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-65529Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-65529Vendor Advisory
FAQ
What is CVE-2021-3453?
CVE-2021-3453 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash sto...
How severe is CVE-2021-3453?
CVE-2021-3453 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3453?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkpad Helix Firmware, Lenovo Thinkpad Helix, Lenovo Thinkpad T550 Firmware, Lenovo Thinkpad T550, Lenovo Thinkpad W550S Firmware.