CVE-2021-3599

EUVD-2021-26905
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
lenovoCNA
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
lenovothinkpad_x380_yoga_firmware
𝑥
< 2020-10-31
lenovothinkpad_x1_fold_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_yoga_260_firmware
𝑥
< 2021-10-25
lenovothinkpad_yoga_11e_3rd_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_yoga_370_firmware
𝑥
< 2021-10-31
lenovothinkpad_x12_detachable_gen_1_firmware
𝑥
< 2021-10-31
lenovothinkpad_yoga_11e_4th_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_yoga_11e_5th_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_x250_firmware
𝑥
< 2021-10-31
lenovothinkpad_x260_firmware
𝑥
< 2021-10-31
lenovothinkpad_x270_firmware
𝑥
< 2021-10-29
lenovothinkpad_10_firmware
𝑥
< 2021-10-25
lenovothinkpad_s2_gen_6_firmware
𝑥
< 2021-10-31
lenovothinkpad_t460p_firmware
𝑥
< 2021-10-29
lenovothinkpad_s2_yoga_gen_6_firmware
𝑥
< 2021-10-31
lenovothinkpad_x1_tablet_gen_3_firmware
𝑥
< 2021-10-29
lenovothinkpad_t460_firmware
𝑥
< 2021-10-31
lenovothinkpad_t14s_firmware
𝑥
< 2021-10-15
lenovothinkpad_t470p_firmware
𝑥
< r0fet55w
lenovothinkpad_t470s_firmware
𝑥
< 2021-10-29
lenovothinkpad_p71_firmware
𝑥
< 2021-10-29
lenovothinkpad_t440p_firmware
𝑥
< 2021-10-29
lenovothinkpad_t15p_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_t15g_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_s540_firmware
𝑥
< 2021-10-25
lenovothinkpad_l380_firmware
𝑥
< 2021-10-31
lenovothinkpad_s5_2nd_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_p15v_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_p17_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_l580_firmware
𝑥
< 2021-10-15
lenovothinkpad_p15_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_l590_firmware
𝑥
< 2021-10-15
lenovothinkpad_l380_yoga_firmware
𝑥
< 2021-10-31
lenovothinkpad_l490_firmware
𝑥
< 2021-10-15
lenovothinkpad_l480_firmware
𝑥
< 2021-10-15
lenovothinkpad_l470_firmware
𝑥
< 2021-10-15
lenovothinkpad_l460_firmware
𝑥
< 2021-10-15
lenovothinkpad_e490_firmware
𝑥
< 2021-10-15
lenovothinkpad_l390_firmware
𝑥
< 2021-10-31
lenovothinkpad_l390_yoga_firmware
𝑥
< 2021-10-31
lenovothinkpad_e15_gen_3_firmware
𝑥
< 2021-10-15
lenovothinkpad_l14_firmware
𝑥
< 2021-10-15
lenovothinkpad_l13_gen_2_firmware
𝑥
< 2021-10-31
lenovothinkpad_l15_firmware
𝑥
< 2021-10-15
lenovothinkpad_l15_gen_2_firmware
𝑥
< 2021-10-15
lenovothinkpad_l13_firmware
𝑥
< 2021-10-31
lenovothinkpad_e14_gen_3_firmware
𝑥
< 2021-10-15
lenovothinkpad_e590_firmware
𝑥
< 2021-10-15
lenovothinkpad_e580_firmware
𝑥
< 2021-10-15
lenovothinkpad_l13_yoga_gen_2_firmware
𝑥
< 2021-10-31
lenovothinkpad_e570_firmware
𝑥
< 2021-10-15
lenovothinkpad_l13_yoga_firmware
𝑥
< 2021-10-31
lenovothinkpad_11e_3rd_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_e480_firmware
𝑥
< 2021-10-15
lenovothinkpad_e14_firmware
𝑥
≤ 2021-10-15
lenovothinkpad_e470_firmware
𝑥
< 2021-10-15
lenovothinkpad_e15_firmware
𝑥
< 2021-10-15
lenovothinkpad_e15_gen_2_firmware
𝑥
< 2021-10-15
lenovothinkpad_e14_gen_2_firmware
𝑥
< 2021-10-15
lenovothinkpad_13_gen_2_firmware
𝑥
< 2021-10-31
lenovothinkpad_11e_4th_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_11e_yoga_gen_6_firmware
𝑥
< 2021-10-31
lenovoideapad_s940-14iwl_firmware
𝑥
≤ 12.0.81.1753
lenovoideapad_yoga_s940-14iwl_firmware
𝑥
≤ 12.0.81.1753
lenovov330-15isk_firmware
𝑥
≤ 11.8.86.3877
lenovov330-15ikb_firmware
𝑥
≤ 11.8.86.3877
lenovov130-15igm_firmware
𝑥
≤ 6vcn42ww
𝑥
= Vulnerable software versions