Unknown
CVE-2019-6156
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- 330 14igm firmware
- 330 15igm firmware
- 510 15ikl firmware
- 510s 08ikl firmware
- 530s 07icb firmware
- aio 910 27ish firmware
- aio y910 27ish firmware
- aio300 23isu(c5130) firmware
- aio520 22ikl firmware
- aio520 22iku firmware
- aio520 24ikl firmware
- aio520 24iku firmware
- aio520 27ikl firmware
- h50 30g desktop firmware
- ideacentre 300 20ish firmware
- ideacentre 300s 11ish firmware
- ideacentre 510 15icb firmware
- ideacentre 510a 15icb firmware
- ideacentre 510s 08ish firmware
- ideacentre 520s 23iku firmware
- ideacentre 620s 03ikl firmware
- ideacentre 700 firmware
- ideacentre 720 18icb firmware
- ideacentre 730s 24ikb firmware
- legion c530 19icb firmware
- legion c730 19ico firmware
- legion t530 28icb firmware
- legion t730 28ico firmware
- legion y520t z370 firmware
- legion y720 tower firmware
- legion y920 tower firmware
- lenovo 63 firmware
- m4500 firmware
- m4500 id firmware
- m4550 id firmware
- qitian 4500 firmware
- qitian b4550 firmware
- qitian b4650 firmware
- qitian m4550 firmware
- qitian m4600 firmware
- qitian m4650 firmware
- qt a7400 firmware
- qt b415 firmware
- qt m410 firmware
- qt m415 firmware
- thinkcenter m700z firmware
- thinkcenter m800z firmware
- thinkcentre e73 (sff) firmware
- thinkcentre e73 (twr) firmware
- thinkcentre e73s firmware
- thinkcentre e74 firmware
- thinkcentre e74s firmware
- thinkcentre e74z firmware
- thinkcentre e75s firmware
- thinkcentre e75t firmware
- thinkcentre e93 (sff) firmware
- thinkcentre e93 (twr) firmware
- thinkcentre e95z firmware
- thinkcentre e96z firmware
- thinkcentre m4500k firmware
- thinkcentre m4500q firmware
- thinkcentre m4500s firmware
- thinkcentre m4500t firmware
- thinkcentre m4600s firmware
- thinkcentre m4600t firmware
- thinkcentre m610 firmware
- thinkcentre m6500s firmware
- thinkcentre m6500t firmware
- thinkcentre m6600 firmware
- thinkcentre m6600q firmware
- thinkcentre m6600s firmware
- thinkcentre m6600t firmware
- thinkcentre m700q firmware
- thinkcentre m700s firmware
- thinkcentre m700t firmware
- thinkcentre m700z firmware
- thinkcentre m710e firmware
- thinkcentre m710q firmware
- thinkcentre m710s firmware
- thinkcentre m710t firmware
- thinkcentre m720q firmware
- thinkcentre m720s firmware
- thinkcentre m720t firmware
- thinkcentre m73 (sff) firmware
- thinkcentre m73 (twr) firmware
- thinkcentre m73 tiny firmware
- thinkcentre m7300z firmware
- thinkcentre m73p firmware
- thinkcentre m800 firmware
- thinkcentre m800z firmware
- thinkcentre m810z firmware
- thinkcentre m818z firmware
- thinkcentre m820z firmware
- thinkcentre m83 (sff) firmware
- thinkcentre m83 (tiny) firmware
- thinkcentre m83 (twr) firmware
- thinkcentre m8300z firmware
- thinkcentre m8350z firmware
- thinkcentre m83z (aio) firmware
- thinkcentre m8500s firmware
- thinkcentre m8500t firmware
- thinkcentre m8600s firmware
- thinkcentre m8600t firmware
- thinkcentre m900 firmware
- thinkcentre m900z firmware
- thinkcentre m910q firmware
- thinkcentre m910s firmware
- thinkcentre m910t firmware
- thinkcentre m910x firmware
- thinkcentre m910z firmware
- thinkcentre m920q firmware
- thinkcentre m920s firmware
- thinkcentre m920t firmware
- thinkcentre m920x firmware
- thinkcentre m920z firmware
- thinkcentre m93 firmware
- thinkcentre m93p (sff) firmware
- thinkcentre m93p (twr) firmware
- thinkcentre m93p tiny firmware
- thinkcentre m9500z firmware
- thinkcentre m9550z firmware
- thinkcentre s510 firmware
- thinkcentre x1 aio firmware
- thinkpad e480 firmware
- thinkpad e560p firmware
- thinkpad e570p firmware
- thinkpad e580 firmware
- thinkpad l480 firmware
- thinkpad l580 firmware
- thinkpad s5 firmware
- thinkpad t460 firmware
- thinkpad t460p firmware
- thinkpad x260 firmware
- thinkpad x380 yoga firmware
- thinkstation c30 refresh firmware
- thinkstation d30 refresh firmware
- thinkstation e32 firmware
- thinkstation p300 firmware
- thinkstation p310 firmware
- thinkstation p318 firmware
- thinkstation p320 firmware
- thinkstation p320 tiny firmware
- thinkstation p330 firmware
- thinkstation p330 tiny firmware
- thinkstation p410 firmware
- thinkstation p500 firmware
- thinkstation p510 firmware
- thinkstation p520 firmware
- thinkstation p520c firmware
- thinkstation p700 firmware
- thinkstation p710 firmware
- thinkstation p720 firmware
- thinkstation p900 firmware
- thinkstation p910 firmware
- thinkstation p920 firmware
- thinkstation s30 refresh firmware
- v310z(yt s3150) firmware
- v410z(yt s4250) firmware
- v510z (yt s5250) firmware
- v520s 08ikl firmware
- v520t 15ikl firmware
- v530 22icb(yt s4350) firmware
- v530 24icb(yt s5350) firmware
- yangtian afh110 firmware
- yangtian afh81 firmware
- yangtian afq150 firmware
- yangtian mc h110 firmware
- yangtian mc h110 pci firmware
- yangtian mc h81 firmware
- yangtian me/we h110 firmware
- yangtian mf/wf h110 pci firmware
- yangtian mf/wf h81 pci firmware
- yangtian ms/ws h81 firmware
- yangtian tc/wc h110 pci firmware
- yangtian tc/wcc h81 pci firmware
- yangtian ytm6900e 00 firmware
- yta8900f firmware
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: