Vulnerability Description
A null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could cause systems to experience a blue screen error.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Power Management Driver | < 1.67.17.54 |
| Lenovo | Thinkpad 11E Gen 5 | - |
| Lenovo | Thinkpad 11E Yoga Gen 6 | - |
| Lenovo | Thinkpad 13 Gen 2 | - |
| Lenovo | Thinkpad 25 | - |
| Lenovo | Thinkpad A275 | - |
| Lenovo | Thinkpad A285 | - |
| Lenovo | Thinkpad A475 | - |
| Lenovo | Thinkpad A485 | - |
| Lenovo | Thinkpad E14 | - |
| Lenovo | Thinkpad E14 Gen2 | - |
| Lenovo | Thinkpad E15 | - |
| Lenovo | Thinkpad E15 Gen2 | - |
| Lenovo | Thinkpad E470 | - |
| Lenovo | Thinkpad E470C | - |
| Lenovo | Thinkpad E475 | - |
| Lenovo | Thinkpad E480 | - |
| Lenovo | Thinkpad E490 | - |
| Lenovo | Thinkpad E495 | - |
| Lenovo | Thinkpad E570 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-59174Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-59174Vendor Advisory
FAQ
What is CVE-2021-3463?
CVE-2021-3463 is a vulnerability with a CVSS score of 4.2 (MEDIUM). A null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could cause systems to experience a blue screen error.
How severe is CVE-2021-3463?
CVE-2021-3463 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3463?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Power Management Driver, Lenovo Thinkpad 11E Gen 5, Lenovo Thinkpad 11E Yoga Gen 6, Lenovo Thinkpad 13 Gen 2, Lenovo Thinkpad 25.