CVE-2020-8353

EUVD-2020-29220
Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
lenovoCNA
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
lenovothinkcentre_m80t_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m80s_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m90t_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m90s_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m910z_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m920s_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m920t_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m920q_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m920z_firmware
𝑥
< 2020-08-10
lenovothinkstation_p330t_firmware
𝑥
< 2020-08-10
lenovothinkstation_p330s_firmware
𝑥
< 2020-08-10
lenovothinkstation_p330_tiny_firmware
𝑥
< 2020-08-10
lenovothinkstation_p340t_firmware
𝑥
< 2020-08-10
lenovothinkstation_p340s_firmware
𝑥
< 2020-08-10
𝑥
= Vulnerable software versions
Common Weakness Enumeration