MEDIUM · 6.7

CVE-2021-3719

A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker wi...

Vulnerability Description

A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoThinkcentre E93 Firmware< fbktdfa
LenovoThinkcentre E93-
LenovoThinkcentre M600 Firmware< m00kt65a
LenovoThinkcentre M600-
LenovoThinkcentre M700 Tiny Firmware< fwktb9a
LenovoThinkcentre M700 Tiny-
LenovoThinkcentre M73 Firmware< fhkt86a
LenovoThinkcentre M73-
LenovoThinkcentre M73P Firmware< fbktdfa
LenovoThinkcentre M73P-
LenovoThinkcentre M800 Firmware< fwktb9a
LenovoThinkcentre M800-
LenovoThinkcentre M818Z Firmware< m1ekt23a
LenovoThinkcentre M818Z-
LenovoThinkcentre M83 Firmware< fbktdfa
LenovoThinkcentre M83-
LenovoThinkcentre M900 Firmware< fwktb9a
LenovoThinkcentre M900-
LenovoThinkcentre M900X Firmware< fwktb9a
LenovoThinkcentre M900X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3719?

CVE-2021-3719 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker wi...

How severe is CVE-2021-3719?

CVE-2021-3719 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3719?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkcentre E93 Firmware, Lenovo Thinkcentre E93, Lenovo Thinkcentre M600 Firmware, Lenovo Thinkcentre M600, Lenovo Thinkcentre M700 Tiny Firmware.