CVE-2020-8353

Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
lenovoCNA
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
VendorProductVersion
lenovothinkcentre_m80t_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m80s_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m90t_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m90s_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m910z_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m920s_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m920t_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m920q_firmware
𝑥
< 2020-08-10
lenovothinkcentre_m920z_firmware
𝑥
< 2020-08-10
lenovothinkstation_p330t_firmware
𝑥
< 2020-08-10
lenovothinkstation_p330s_firmware
𝑥
< 2020-08-10
lenovothinkstation_p330_tiny_firmware
𝑥
< 2020-08-10
lenovothinkstation_p340t_firmware
𝑥
< 2020-08-10
lenovothinkstation_p340s_firmware
𝑥
< 2020-08-10
𝑥
= Vulnerable software versions
Common Weakness Enumeration