CVE-2020-8353

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/11/2020
Last modified:
30/11/2020

Description

Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:thinkcentre_m80t_firmware:*:*:*:*:*:*:*:* 2020-08-10 (excluding)
cpe:2.3:h:lenovo:thinkcentre_m80t:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkcentre_m80s_firmware:*:*:*:*:*:*:*:* 2020-08-10 (excluding)
cpe:2.3:h:lenovo:thinkcentre_m80s:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkcentre_m90t_firmware:*:*:*:*:*:*:*:* 2020-08-10 (excluding)
cpe:2.3:h:lenovo:thinkcentre_m90t:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkcentre_m90s_firmware:*:*:*:*:*:*:*:* 2020-08-10 (excluding)
cpe:2.3:h:lenovo:thinkcentre_m90s:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkcentre_m910z_firmware:*:*:*:*:*:*:*:* 2020-08-10 (excluding)
cpe:2.3:h:lenovo:thinkcentre_m910z:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkcentre_m920s_firmware:*:*:*:*:*:*:*:* 2020-08-10 (excluding)
cpe:2.3:h:lenovo:thinkcentre_m920s:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkcentre_m920t_firmware:*:*:*:*:*:*:*:* 2020-08-10 (excluding)
cpe:2.3:h:lenovo:thinkcentre_m920t:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkcentre_m920q_firmware:*:*:*:*:*:*:*:* 2020-08-10 (excluding)


References to Advisories, Solutions, and Tools