CVE-2017-3740

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/06/2017
Last modified:
20/04/2025

Description

In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lenovo:active_protection_system:1.00b:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.01b:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.20b:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.21:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.22:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.23:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.30b:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.31:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.32:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.33b:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.34:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.40:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.41:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.50:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:active_protection_system:1.51:*:*:*:*:*:*:*