CVE-2018-9069

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
lenovoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
VendorProductVersion
hp310s-14isk_firmware
𝑥
< 1.15
hp320-15ikbra_firmware
𝑥
< 6jcn24ww
hp320-15ikbrn_firmware
𝑥
< 6jcn24ww
hp320-15ikbrn_touch_firmware
𝑥
< 6jcn24ww
hp320-17ikbrn
𝑥
< 2.09
hp320s-14ikb
𝑥
< 2.09
hp320s-15ikb_firmware
𝑥
< 2.09
hp320s-15isk_firmware
𝑥
< 2wcn38ww
hp510s-14isk_firmware
𝑥
< 1.15
hp520-15ikbrn_firmware
𝑥
< 6jcn26ww
hp520s-14ikb_firmware
𝑥
< 2.09
hp710s_plus-13ikb_16g_firmware
𝑥
< 2.55
hp710s_plus-3ikb_firmware
𝑥
< 2.55
hpxiaoxinair13ikbpro_firmware
𝑥
< 2.55
hp710s_plus_touch-13ikb_firmware
𝑥
< 2.55
hp720s-13ikb_firmware
𝑥
< 5scn38ww
hpb320-14ikb_firmware
-
lenovoe42-80_firmware
𝑥
< 2wcn38ww
lenovoe52-80_firmware
𝑥
< 2wcn38ww
hpflex_4-1470_firmware
𝑥
< 1.15
hpflex_5-1470_firmware
𝑥
< 2.09
hpflex_5-1570_firmware
𝑥
< 2.09
hpideapad_2in1_14_firmware
-
hplenovo_ideapad_320-14ikb\(i\+a\)_firmware
-
hplenovo_ideapad_320-14ikb\(i\+n\)_firmware
-
hplenovo_ideapad_320-15abr_firmware
-
hplenovo_ideapad_320-15ikb\(i\+n\)_firmware
-
hplenovo_ideapad_320s-14ikbr_firmware
-
hplenovo_ideapad_320s-15ikbr_firmware
-
hplenovo_ideapad_520s-14ikbr_firmware
-
hplenovo_ideapad_720s-14ikb_firmware
𝑥
< 6jcn26ww
hplenovo_ideapad_flex_5-1470_firmware
𝑥
< 6jcn26ww
hplenovo_ideapad_flex_5-1570_firmware
𝑥
< 6jcn26ww
hplenovo_ideapad_y520-15ikbn_firmware
-
hplenovo_tianyi_310-14ikb_firmware
-
hplenovo_tianyi_310-15ikb_firmware
-
hplenovo_y520-15ikba_firmware
𝑥
< 5jcn25ww
hplenovo_y520-15ikbm_firmware
𝑥
< 5jcn25ww
hplenovo_yoga_520-14ikb_firmware
𝑥
< 6jcn26ww
hplenovo_yoga_520-15ikb_firmware
𝑥
< 6jcn26ww
hpmiix_720-12ikb
𝑥
< 3scn66ww
hpnano110-14ikb_firmware
-
hpnano110-15ikb_firmware
𝑥
< 5xcn24ww
hprescuer_r720-15ikbm_firmware
𝑥
< 5xcn24ww
hprescuer_y520-15ikbm_firmware
𝑥
< 5xcn24ww
lenovov310-14ikb_firmware
𝑥
< 2wcn38ww
lenovov310-14isk_firmware
𝑥
< 4.07
lenovov310-15ikb_firmware
𝑥
< 2wcn38ww
lenovov310-15isk_firmware
𝑥
< 0zcn47ww
hpv330-14ikb_firmware
𝑥
< 4.07
hpv330-14isk_firmware
𝑥
< 4.07
lenovov510-14ikb_firmware
𝑥
< 2wcn38ww
lenovov510-15ikb_firmware
𝑥
< 2wcn38ww
hpyoga_310-11iap_firmware
𝑥
< 6.7
hpyoga_510-14isk_firmware
𝑥
< 1.15
hpyoga_720-13ikb_firmware
𝑥
< 2.05
hpyoga_720-13ikbr_firmware
𝑥
< 2.07
hpyoga_720-15ikb_firmware
𝑥
< 2.05
hplenovo_v720-14_firmware
𝑥
< 2.12
hp7000_u42_firmware
𝑥
< 2.09
hp7000-15_u42_firmware
𝑥
< 2.09
hpr720-15ikba_firmware
𝑥
< 5jcn25ww
hpy520-15ikba_firmware
𝑥
< 5jcn25ww
hpr720-15ikbn_firmware
𝑥
< 4gcn38ww
hpy520-15ikbn_firmware
𝑥
< 4gcn38ww
hpy720-15ikb_firmware
𝑥
< 4gcn38ww
hplenovo_y720-15ikb_firmware
𝑥
< 4gcn38ww
hpe43-80_kbl_firmware
𝑥
< 4.07
𝑥
= Vulnerable software versions