CVE-2020-8353
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/11/2020
Last modified:
30/11/2020
Description
Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:lenovo:thinkcentre_m80t_firmware:*:*:*:*:*:*:*:* | 2020-08-10 (excluding) | |
| cpe:2.3:h:lenovo:thinkcentre_m80t:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkcentre_m80s_firmware:*:*:*:*:*:*:*:* | 2020-08-10 (excluding) | |
| cpe:2.3:h:lenovo:thinkcentre_m80s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkcentre_m90t_firmware:*:*:*:*:*:*:*:* | 2020-08-10 (excluding) | |
| cpe:2.3:h:lenovo:thinkcentre_m90t:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkcentre_m90s_firmware:*:*:*:*:*:*:*:* | 2020-08-10 (excluding) | |
| cpe:2.3:h:lenovo:thinkcentre_m90s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkcentre_m910z_firmware:*:*:*:*:*:*:*:* | 2020-08-10 (excluding) | |
| cpe:2.3:h:lenovo:thinkcentre_m910z:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkcentre_m920s_firmware:*:*:*:*:*:*:*:* | 2020-08-10 (excluding) | |
| cpe:2.3:h:lenovo:thinkcentre_m920s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkcentre_m920t_firmware:*:*:*:*:*:*:*:* | 2020-08-10 (excluding) | |
| cpe:2.3:h:lenovo:thinkcentre_m920t:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkcentre_m920q_firmware:*:*:*:*:*:*:*:* | 2020-08-10 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



