A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain conditions during a BIOS update performed by Lenovo Vantage.
When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ideapad_1-11ada05_firmware | Lenovo | fqcn19ww (including) | fqcn19ww (including) |