MEDIUM · 6.7

CVE-2021-3971

A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with ele...

Vulnerability Description

A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoIdeapad 3-14Ada05 Firmware< e8cn33ww
LenovoIdeapad 3-14Ada05-
LenovoIdeapad 3-14Ada6 Firmware< hbcn21ww
LenovoIdeapad 3-14Ada6-
LenovoIdeapad 3-14Alc6 Firmware< glcn43ww
LenovoIdeapad 3-14Alc6-
LenovoIdeapad 3-14Are05 Firmware< dzcn42ww
LenovoIdeapad 3-14Are05-
LenovoIdeapad 3-15Ada6 Firmware< hbcn21ww
LenovoIdeapad 3-15Ada6-
LenovoIdeapad 3-15Alc6 Firmware< glcn43ww
LenovoIdeapad 3-15Alc6-
LenovoIdeapad 3-15Are05 Firmware< dzcn42ww
LenovoIdeapad 3-15Are05-
LenovoIdeapad 3-15Igl05 Firmware< dvcn23ww
LenovoIdeapad 3-15Igl05-
LenovoIdeapad 3-17Ada05 Firmware< e8cn33ww
LenovoIdeapad 3-17Ada05-
LenovoIdeapad 3-17Ada6 Firmware< hbcn21ww
LenovoIdeapad 3-17Ada6-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3971?

CVE-2021-3971 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with ele...

How severe is CVE-2021-3971?

CVE-2021-3971 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3971?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Ideapad 3-14Ada05 Firmware, Lenovo Ideapad 3-14Ada05, Lenovo Ideapad 3-14Ada6 Firmware, Lenovo Ideapad 3-14Ada6, Lenovo Ideapad 3-14Alc6 Firmware.