CVE-2021-3718

A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
lenovoCNA
4.3 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
VendorProductVersion
lenovothinkpad_11e_3rd_gen_firmware
𝑥
≤ 1.22
lenovothinkpad_11e_3rd_gen_firmware
𝑥
≤ 1.29
lenovothinkpad_11e_4th_gen_i3_firmware
𝑥
≤ 1.22
lenovothinkpad_11e_4th_gen_i7_firmware
𝑥
≤ 1.22
lenovothinkpad_11e_4th_gen_i5_firmware
𝑥
≤ 1.22
lenovothinkpad_11e_4th_gen_celeron_firmware
𝑥
≤ 1.27
lenovothinkpad_11e_yoga_gen_6_firmware
𝑥
≤ 1.12
lenovothinkpad_13_gen_2_firmware
𝑥
≤ 1.29
lenovothinkpad_e490_firmware
𝑥
≤ 1.30
lenovothinkpad_e490s_firmware
𝑥
≤ 1.30
lenovothinkpad_e590_firmware
𝑥
≤ 1.30
lenovothinkpad_l13_firmware
𝑥
≤ 1.31
lenovothinkpad_l13_gen_2_firmware
𝑥
≤ 1.11
lenovothinkpad_l13_gen_2_firmware
𝑥
≤ 1.08
lenovothinkpad_l13_yoga_firmware
𝑥
≤ 1.31
lenovothinkpad_l13_yoga_gen_2_firmware
𝑥
≤ 1.11
lenovothinkpad_l13_yoga_gen_2_firmware
𝑥
≤ 1.08
lenovothinkpad_l14_gen_1_firmware
𝑥
< 1.15
lenovothinkpad_l14_firmware
𝑥
< 1.20.1.17
lenovothinkpad_l15_gen_1_firmware
𝑥
< 1.15
lenovothinkpad_l15_firmware
𝑥
< 1.20.1.17
lenovothinkpad_l380_firmware
𝑥
≤ 1.26
lenovothinkpad_l380_yoga_firmware
𝑥
≤ 1.26
lenovothinkpad_l390_yoga_firmware
𝑥
≤ 1.35
lenovothinkpad_l390_firmware
𝑥
≤ 1.35
lenovothinkpad_l490_firmware
𝑥
< 1.26
lenovothinkpad_l590_firmware
𝑥
< 1.26
lenovothinkpad_s5_2nd_gen_firmware
𝑥
≤ 1.28
lenovothinkpad_t460_firmware
𝑥
≤ 1.43.1.11
lenovothinkpad_s2_gen_6_firmware
𝑥
≤ 2021-09-30
lenovothinkpad_s2_yoga_gen_6_firmware
𝑥
≤ 2021-09-30
lenovothinkpad_x12_detachable_gen_1_firmware
𝑥
< 1.16
lenovothinkpad_x260_firmware
𝑥
≤ 1.47\/1.15
lenovothinkpad_x380_yoga_firmware
𝑥
≤ 1.34
lenovothinkpad_11e_5th_gen_firmware
𝑥
≤ 1.13
lenovothinkpad_11e_5th_gen_firmware
𝑥
≤ 1.13
𝑥
= Vulnerable software versions