CVE Vulnerabilities

CVE-2021-3599

Published: Nov 12, 2021 | Modified: Nov 24, 2021
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Affected Software

Name Vendor Start Version End Version
Thinkpad_x380_yoga_firmware Lenovo * 2020-10-31 (excluding)

References