CVE-2021-3519

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
12/11/2021
Last modified:
19/11/2021

Description

A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:ideacentre_c5-14mb05_firmware:*:*:*:*:*:*:*:* o4hkt33a (excluding)
cpe:2.3:h:lenovo:ideacentre_c5-14mb05:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:ideacentre_3-07imb05_firmware:*:*:*:*:*:*:*:* m2vkt18a (excluding)
cpe:2.3:h:lenovo:ideacentre_3-07imb05:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:ideacentre_5-14imb05_firmware:*:*:*:*:*:*:*:* o4hkt33a (excluding)
cpe:2.3:h:lenovo:ideacentre_5-14imb05:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:ideacentre_5-14iob6_firmware:*:*:*:*:*:*:*:* m3gkt29a (excluding)
cpe:2.3:h:lenovo:ideacentre_5-14iob6:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:ideacentre_creator_5-14iob6_firmware:*:*:*:*:*:*:*:* m3gkt29a (excluding)
cpe:2.3:h:lenovo:ideacentre_creator_5-14iob6:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:ideacentre_g5-14imb05_firmware:*:*:*:*:*:*:*:* o4hkt33a (excluding)
cpe:2.3:h:lenovo:ideacentre_g5-14imb05:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:ideacentre_gaming_5-14iob6_firmware:*:*:*:*:*:*:*:* m3gkt29a (excluding)
cpe:2.3:h:lenovo:ideacentre_gaming_5-14iob6:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkcentre_m60e_tiny_firmware:*:*:*:*:*:*:*:* m3skt1ea (excluding)


References to Advisories, Solutions, and Tools