MEDIUM · 6.4

CVE-2021-3519

A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.

Vulnerability Description

A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.

CVSS Score

6.4

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
LenovoIdeacentre C5-14Mb05 Firmware< o4hkt33a
LenovoIdeacentre C5-14Mb05-
LenovoIdeacentre 3-07Imb05 Firmware< m2vkt18a
LenovoIdeacentre 3-07Imb05-
LenovoIdeacentre 5-14Imb05 Firmware< o4hkt33a
LenovoIdeacentre 5-14Imb05-
LenovoIdeacentre 5-14Iob6 Firmware< m3gkt29a
LenovoIdeacentre 5-14Iob6-
LenovoIdeacentre Creator 5-14Iob6 Firmware< m3gkt29a
LenovoIdeacentre Creator 5-14Iob6-
LenovoIdeacentre G5-14Imb05 Firmware< o4hkt33a
LenovoIdeacentre G5-14Imb05-
LenovoIdeacentre Gaming 5-14Iob6 Firmware< m3gkt29a
LenovoIdeacentre Gaming 5-14Iob6-
LenovoThinkcentre M60E Tiny Firmware< m3skt1ea
LenovoThinkcentre M60E Tiny-
LenovoThinkcentre M630E Firmware< m28kt36a
LenovoThinkcentre M630E-
LenovoThinkcentre M70A Firmware<= m2skt21a
LenovoThinkcentre M70A-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3519?

CVE-2021-3519 is a vulnerability with a CVSS score of 6.4 (MEDIUM). A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.

How severe is CVE-2021-3519?

CVE-2021-3519 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3519?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Ideacentre C5-14Mb05 Firmware, Lenovo Ideacentre C5-14Mb05, Lenovo Ideacentre 3-07Imb05 Firmware, Lenovo Ideacentre 3-07Imb05, Lenovo Ideacentre 5-14Imb05 Firmware.