Vulnerability Description
A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkpad 11E 3Rd Gen Firmware | <= 1.22 |
| Lenovo | Thinkpad 11E 3Rd Gen | - |
| Lenovo | Thinkpad 11E 4Th Gen I3 Firmware | <= 1.22 |
| Lenovo | Thinkpad 11E 4Th Gen I3 | - |
| Lenovo | Thinkpad 11E 4Th Gen I7 Firmware | <= 1.22 |
| Lenovo | Thinkpad 11E 4Th Gen I7 | - |
| Lenovo | Thinkpad 11E 4Th Gen I5 Firmware | <= 1.22 |
| Lenovo | Thinkpad 11E 4Th Gen I5 | - |
| Lenovo | Thinkpad 11E 4Th Gen Celeron Firmware | <= 1.27 |
| Lenovo | Thinkpad 11E 4Th Gen Celeron | - |
| Lenovo | Thinkpad 11E Yoga Gen 6 Firmware | <= 1.12 |
| Lenovo | Thinkpad 11E Yoga Gen 6 | - |
| Lenovo | Thinkpad 13 Gen 2 Firmware | <= 1.29 |
| Lenovo | Thinkpad 13 Gen 2 | - |
| Lenovo | Thinkpad L13 Firmware | <= 1.31 |
| Lenovo | Thinkpad L13 | - |
| Lenovo | Thinkpad L13 Gen 2 Firmware | <= 1.11 |
| Lenovo | Thinkpad L13 Gen 2 | - |
| Lenovo | Thinkpad L13 Yoga Firmware | <= 1.31 |
| Lenovo | Thinkpad L13 Yoga | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-72619Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-72619Vendor Advisory
FAQ
What is CVE-2021-3843?
CVE-2021-3843 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
How severe is CVE-2021-3843?
CVE-2021-3843 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3843?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkpad 11E 3Rd Gen Firmware, Lenovo Thinkpad 11E 3Rd Gen, Lenovo Thinkpad 11E 4Th Gen I3 Firmware, Lenovo Thinkpad 11E 4Th Gen I3, Lenovo Thinkpad 11E 4Th Gen I7 Firmware.