CVE Vulnerabilities

CVE-2021-3786

Published: Nov 12, 2021 | Modified: Nov 26, 2021
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.

Affected Software

Name Vendor Start Version End Version
Thinkpad_x380_yoga_firmware Lenovo * 2020-10-31 (excluding)

References