CVE-2019-6171

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/08/2019
Last modified:
19/10/2022

Description

A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:20f1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:20f1:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:20f2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:20f2:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:20jq_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:20jq:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:20jr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:20jr:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:20g9_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:20g9:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:20gb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:20gb:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:20g8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:20g8:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:20ga_firmware:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools