CVE Vulnerabilities

CVE-2021-3843

Published: Nov 12, 2021 | Modified: Nov 23, 2021
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Affected Software

Name Vendor Start Version End Version
Thinkpad_11e_3rd_gen_firmware Lenovo * 1.22 (including)

References