CVE-2021-3786

A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
lenovoCNA
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
lenovothinkpad_x380_yoga_firmware
𝑥
< 2020-10-31
lenovothinkpad_x1_fold_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_yoga_260_firmware
𝑥
< 2021-10-25
lenovothinkpad_yoga_11e_3rd_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_yoga_370_firmware
𝑥
< 2021-10-31
lenovothinkpad_x12_detachable_gen_1_firmware
𝑥
< 2021-10-31
lenovothinkpad_yoga_11e_4th_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_yoga_11e_5th_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_x250_firmware
𝑥
< 2021-10-31
lenovothinkpad_x260_firmware
𝑥
< 2021-10-31
lenovothinkpad_x270_firmware
𝑥
< 2021-10-29
lenovothinkpad_10_firmware
𝑥
< 2021-10-25
lenovothinkpad_s2_gen_6_firmware
𝑥
< 2021-10-31
lenovothinkpad_t460p_firmware
𝑥
< 2021-10-29
lenovothinkpad_s2_yoga_gen_6_firmware
𝑥
< 2021-10-31
lenovothinkpad_x1_tablet_gen_3_firmware
𝑥
< 2021-10-29
lenovothinkpad_t460_firmware
𝑥
< 2021-10-31
lenovothinkpad_t14s_firmware
𝑥
< 2021-10-15
lenovothinkpad_t470p_firmware
𝑥
< r0fet55w
lenovothinkpad_t470s_firmware
𝑥
< 2021-10-29
lenovothinkpad_p71_firmware
𝑥
< 2021-10-29
lenovothinkpad_t440p_firmware
𝑥
< 2021-10-29
lenovothinkpad_t15p_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_t15g_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_s540_firmware
𝑥
< 2021-10-25
lenovothinkpad_l380_firmware
𝑥
< 2021-10-31
lenovothinkpad_s5_2nd_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_p15v_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_p17_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_l580_firmware
𝑥
< 2021-10-15
lenovothinkpad_p15_gen_1_firmware
𝑥
< 2021-10-29
lenovothinkpad_l590_firmware
𝑥
< 2021-10-15
lenovothinkpad_l380_yoga_firmware
𝑥
< 2021-10-31
lenovothinkpad_l490_firmware
𝑥
< 2021-10-15
lenovothinkpad_l480_firmware
𝑥
< 2021-10-15
lenovothinkpad_l470_firmware
𝑥
< 2021-10-15
lenovothinkpad_l460_firmware
𝑥
< 2021-10-15
lenovothinkpad_e490_firmware
𝑥
< 2021-10-15
lenovothinkpad_l390_firmware
𝑥
< 2021-10-31
lenovothinkpad_l390_yoga_firmware
𝑥
< 2021-10-31
lenovothinkpad_e15_gen_3_firmware
𝑥
< 2021-10-15
lenovothinkpad_l14_firmware
𝑥
< 2021-10-15
lenovothinkpad_l13_gen_2_firmware
𝑥
< 2021-10-31
lenovothinkpad_l15_firmware
𝑥
< 2021-10-15
lenovothinkpad_l15_gen_2_firmware
𝑥
< 2021-10-15
lenovothinkpad_l13_firmware
𝑥
< 2021-10-31
lenovothinkpad_e14_gen_3_firmware
𝑥
< 2021-10-15
lenovothinkpad_e590_firmware
𝑥
< 2021-10-15
lenovothinkpad_e580_firmware
𝑥
< 2021-10-15
lenovothinkpad_l13_yoga_gen_2_firmware
𝑥
< 2021-10-31
lenovothinkpad_e570_firmware
𝑥
< 2021-10-15
lenovothinkpad_l13_yoga_firmware
𝑥
< 2021-10-31
lenovothinkpad_11e_3rd_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_e480_firmware
𝑥
< 2021-10-15
lenovothinkpad_e14_firmware
𝑥
≤ 2021-10-15
lenovothinkpad_e470_firmware
𝑥
< 2021-10-15
lenovothinkpad_e15_firmware
𝑥
< 2021-10-15
lenovothinkpad_e15_gen_2_firmware
𝑥
< 2021-10-15
lenovothinkpad_e14_gen_2_firmware
𝑥
< 2021-10-15
lenovothinkpad_13_gen_2_firmware
𝑥
< 2021-10-31
lenovothinkpad_11e_4th_gen_firmware
𝑥
< 2021-10-31
lenovothinkpad_11e_yoga_gen_6_firmware
𝑥
< 2021-10-31
lenovoideapad_s940-14iwl_firmware
𝑥
≤ 12.0.81.1753
lenovoideapad_yoga_s940-14iwl_firmware
𝑥
≤ 12.0.81.1753
lenovov330-15isk_firmware
𝑥
≤ 11.8.86.3877
lenovov330-15ikb_firmware
𝑥
≤ 11.8.86.3877
lenovov130-15igm_firmware
𝑥
≤ 6vcn42ww
𝑥
= Vulnerable software versions