Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
High
Attack Vector
Local
1

CVE-2021-3843

Disclosure Date: November 12, 2021
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
6.7 Medium
Impact Score:
5.9
Exploitability Score:
0.8
Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • lenovo

Products

  • thinkpad 11e 3rd gen firmware,
  • thinkpad 11e 4th gen celeron firmware,
  • thinkpad 11e 4th gen i3 firmware,
  • thinkpad 11e 4th gen i5 firmware,
  • thinkpad 11e 4th gen i7 firmware,
  • thinkpad 11e 5th gen firmware,
  • thinkpad 11e yoga gen 6 firmware,
  • thinkpad 13 gen 2 firmware,
  • thinkpad l13 firmware,
  • thinkpad l13 gen 2 firmware,
  • thinkpad l13 yoga firmware,
  • thinkpad l13 yoga gen 2 firmware,
  • thinkpad l14 firmware,
  • thinkpad l14 gen 1 firmware,
  • thinkpad l15 firmware,
  • thinkpad l15 gen 1 firmware,
  • thinkpad l380 firmware,
  • thinkpad l380 yoga firmware,
  • thinkpad l390 firmware,
  • thinkpad l390 yoga firmware,
  • thinkpad s2 gen 6 firmware,
  • thinkpad s2 yoga gen 6 firmware,
  • thinkpad s5 2nd gen firmware,
  • thinkpad t460 firmware,
  • thinkpad x1 fold gen 1 firmware,
  • thinkpad x12 detachable gen 1 firmware,
  • thinkpad x260 firmware,
  • thinkpad x380 yoga firmware,
  • thinkpad x390 yoga firmware

Additional Info

Technical Analysis