CVE Vulnerabilities

CVE-2020-8320

Active Debug Code

Published: Jun 09, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

Weakness

The product is released with debugging code still enabled or active.

Affected Software

NameVendorStart VersionEnd Version
Thinkpad_11e_yoga_gen_6_firmwareLenovo*2020-07-10 (excluding)

Potential Mitigations

References