Versio.io

CVE-2021-3971

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 22-04-2022 11:15
Last modified: - 06-05-2022 10:57
Total changes: - 3

Description

A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Low
Attack complexity
Local
Attack vector
High
Availability
High
Confidentiality
High
Integrity
High
Privileges required
Unchanged
Scope
None
User interaction
6.7
Base score
0.8
5.9
Exploitability score
Impact score
 

Verification logic

OR
AND
OR
vendor=lenovo AND product=ideapad_3-14ada05_firmware AND versionEndExcluding=e8cn33ww
OR
vendor=lenovo AND product=ideapad_3-14ada05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14ada6_firmware AND versionEndExcluding=hbcn21ww
OR
vendor=lenovo AND product=ideapad_3-14ada6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14alc6_firmware AND versionEndExcluding=glcn43ww
OR
vendor=lenovo AND product=ideapad_3-14alc6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14are05_firmware AND versionEndExcluding=dzcn42ww
OR
vendor=lenovo AND product=ideapad_3-14are05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15ada6_firmware AND versionEndExcluding=hbcn21ww
OR
vendor=lenovo AND product=ideapad_3-15ada6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15alc6_firmware AND versionEndExcluding=glcn43ww
OR
vendor=lenovo AND product=ideapad_3-15alc6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15are05_firmware AND versionEndExcluding=dzcn42ww
OR
vendor=lenovo AND product=ideapad_3-15are05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15igl05_firmware AND versionEndExcluding=dvcn23ww
OR
vendor=lenovo AND product=ideapad_3-15igl05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17ada05_firmware AND versionEndExcluding=e8cn33ww
OR
vendor=lenovo AND product=ideapad_3-17ada05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17ada6_firmware AND versionEndExcluding=hbcn21ww
OR
vendor=lenovo AND product=ideapad_3-17ada6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17alc6_firmware AND versionEndExcluding=glcn43ww
OR
vendor=lenovo AND product=ideapad_3-17alc6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17are05_firmware AND versionEndExcluding=dzcn42ww
OR
vendor=lenovo AND product=ideapad_3-17are05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17iil05_firmware AND versionEndExcluding=emcn52ww
OR
vendor=lenovo AND product=ideapad_3-17iil05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15ada05_firmware AND versionEndExcluding=e8cn33ww
OR
vendor=lenovo AND product=ideapad_3-15ada05 AND version=-
AND
OR
vendor=lenovo AND product=l3-15itl6_firmware AND versionEndExcluding=gfcn23ww
OR
vendor=lenovo AND product=l3-15itl6 AND version=-
AND
OR
vendor=lenovo AND product=l340-15irh_firmware AND versionEndExcluding=bgcn35ww
OR
vendor=lenovo AND product=l340-15irh AND version=-
AND
OR
vendor=lenovo AND product=l340-15iwl_firmware AND versionEndExcluding=atcn46ww
OR
vendor=lenovo AND product=l340-15iwl AND version=-
AND
OR
vendor=lenovo AND product=l340-15iwl_touch_firmware AND versionEndExcluding=atcn46ww
OR
vendor=lenovo AND product=l340-15iwl_touch AND version=-
AND
OR
vendor=lenovo AND product=l340-17irh_firmware AND versionEndExcluding=bgcn35ww
OR
vendor=lenovo AND product=l340-17irh AND version=-
AND
OR
vendor=lenovo AND product=l340-17iwl_firmware AND versionEndExcluding=atcn46ww
OR
vendor=lenovo AND product=l340-17iwl AND version=-
AND
OR
vendor=lenovo AND product=legion_5_pro-16ach6_firmware AND versionEndExcluding=hhcn25ww
OR
vendor=lenovo AND product=legion_5_pro-16ach6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5_pro-16ach6h_firmware AND versionEndExcluding=gkcn51ww
OR
vendor=lenovo AND product=legion_5_pro-16ach6h AND version=-
AND
OR
vendor=lenovo AND product=legion_5_pro-16ith6_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5_pro-16ith6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5_pro-16ith6h_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5_pro-16ith6h AND version=-
AND
OR
vendor=lenovo AND product=legion_5-15ach6_firmware AND versionEndExcluding=hhcn25ww
OR
vendor=lenovo AND product=legion_5-15ach6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5-15ach6a_firmware AND versionEndExcluding=g9cn28ww
OR
vendor=lenovo AND product=legion_5-15ach6a AND version=-
AND
OR
vendor=lenovo AND product=legion_5-15ach6h_firmware AND versionEndExcluding=gkcn51ww
OR
vendor=lenovo AND product=legion_5-15ach6h AND version=-
AND
OR
vendor=lenovo AND product=legion_5-15ith6_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5-15ith6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5-15ith6h_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5-15ith6h AND version=-
AND
OR
vendor=lenovo AND product=legion_5-17ach6_firmware AND versionEndExcluding=hhcn25ww
OR
vendor=lenovo AND product=legion_5-17ach6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5-17ach6h_firmware AND versionEndExcluding=gkcn51ww
OR
vendor=lenovo AND product=legion_5-17ach6h AND version=-
AND
OR
vendor=lenovo AND product=legion_5-17ith6_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5-17ith6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5-17ith6h_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5-17ith6h AND version=-
AND
OR
vendor=lenovo AND product=legion_7-16achg6_firmware AND versionEndExcluding=gkcn51ww
OR
vendor=lenovo AND product=legion_7-16achg6 AND version=-
AND
OR
vendor=lenovo AND product=legion_7-16ithg6_firmware AND versionEndExcluding=gkcn51ww
OR
vendor=lenovo AND product=legion_7-16ithg6 AND version=-
AND
OR
vendor=lenovo AND product=legion_y540-15irh_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y540-15irh AND version=-
AND
OR
vendor=lenovo AND product=legion_y540-15irh-pg0_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y540-15irh-pg0 AND version=-
AND
OR
vendor=lenovo AND product=legion_y540-17irh_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y540-17irh AND version=-
AND
OR
vendor=lenovo AND product=legion_y540-17irh-pg0_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y540-17irh-pg0 AND version=-
AND
OR
vendor=lenovo AND product=legion_y545_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y545 AND version=-
AND
OR
vendor=lenovo AND product=legion_y545-pg0_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y545-pg0 AND version=-
AND
OR
vendor=lenovo AND product=legion_y7000-2019_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y7000-2019 AND version=-
AND
OR
vendor=lenovo AND product=legion_y7000-2019-pg0_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y7000-2019-pg0 AND version=-
AND
OR
vendor=lenovo AND product=s145-14api_firmware AND versionEndExcluding=bucn31ww
OR
vendor=lenovo AND product=s145-14api AND version=-
AND
OR
vendor=lenovo AND product=s145-14ast_firmware AND versionEndExcluding=aycn26ww
OR
vendor=lenovo AND product=s145-14ast AND version=-
AND
OR
vendor=lenovo AND product=s145-14igm_firmware AND versionEndExcluding=awcn28ww
OR
vendor=lenovo AND product=s145-14igm AND version=-
AND
OR
vendor=lenovo AND product=s145-14iil_firmware AND versionEndExcluding=dkcn54ww
OR
vendor=lenovo AND product=s145-14iil AND version=-
AND
OR
vendor=lenovo AND product=s145-15api_firmware AND versionEndExcluding=bucn31ww
OR
vendor=lenovo AND product=s145-15api AND version=-
AND
OR
vendor=lenovo AND product=s145-15ast_firmware AND versionEndExcluding=aycn26ww
OR
vendor=lenovo AND product=s145-15ast AND version=-
AND
OR
vendor=lenovo AND product=s145-15igm_firmware AND versionEndExcluding=awcn28ww
OR
vendor=lenovo AND product=s145-15igm AND version=-
AND
OR
vendor=lenovo AND product=s145-15iil_firmware AND versionEndExcluding=dkcn54ww
OR
vendor=lenovo AND product=s145-15iil AND version=-
AND
OR
vendor=lenovo AND product=s540-13api_firmware AND versionEndExcluding=cxcn34ww
OR
vendor=lenovo AND product=s540-13api AND version=-
AND
OR
vendor=lenovo AND product=v14_g2-acl_firmware AND versionEndExcluding=glcn43ww
OR
vendor=lenovo AND product=v14_g2-acl AND version=-
AND
OR
vendor=lenovo AND product=v14-ada_firmware AND versionEndExcluding=e8cn33ww
OR
vendor=lenovo AND product=v14-ada AND version=-
AND
OR
vendor=lenovo AND product=v14-are_firmware AND versionEndExcluding=dzcn42ww
OR
vendor=lenovo AND product=v14-are AND version=-
AND
OR
vendor=lenovo AND product=v14-igl_firmware AND versionEndExcluding=dvcn23ww
OR
vendor=lenovo AND product=v14-igl AND version=-
AND
OR
vendor=lenovo AND product=v14-iil_firmware AND versionEndExcluding=dkcn54ww
OR
vendor=lenovo AND product=v14-iil AND version=-
AND
OR
vendor=lenovo AND product=v140-15iwl_firmware AND versionEndExcluding=atcn46ww
OR
vendor=lenovo AND product=v140-15iwl AND version=-
AND
OR
vendor=lenovo AND product=v15_g2-alc_firmware AND versionEndExcluding=glcn43ww
OR
vendor=lenovo AND product=v15_g2-alc AND version=-
AND
OR
vendor=lenovo AND product=v15-ada_firmware AND versionEndExcluding=e8cn33ww
OR
vendor=lenovo AND product=v15-ada AND version=-
AND
OR
vendor=lenovo AND product=v15-igl_firmware AND versionEndExcluding=dvcn23ww
OR
vendor=lenovo AND product=v15-igl AND version=-
AND
OR
vendor=lenovo AND product=v15-iil_firmware AND versionEndExcluding=dkcn54ww
OR
vendor=lenovo AND product=v15-iil AND version=-
AND
OR
vendor=lenovo AND product=v17-iil_firmware AND versionEndExcluding=emcn52ww
OR
vendor=lenovo AND product=v17-iil AND version=-
AND
OR
vendor=lenovo AND product=v340-17iwl_firmware AND versionEndExcluding=atcn46ww
OR
vendor=lenovo AND product=v340-17iwl AND version=-
AND
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5_d_firmware AND versionEndExcluding=hecn24ww
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5_d AND version=-
AND
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5_od_firmware AND versionEndExcluding=hecn24ww
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5_od AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14iil05_firmware AND versionEndExcluding=dvcn23ww
OR
vendor=lenovo AND product=ideapad_3-14iil05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14igl05_firmware AND versionEndExcluding=emcn52ww
OR
vendor=lenovo AND product=ideapad_3-14igl05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15iil05_firmware AND versionEndExcluding=emcn52ww
OR
vendor=lenovo AND product=ideapad_3-15iil05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_5-15are05_firmware AND versionEndExcluding=e7cn44ww
OR
vendor=lenovo AND product=ideapad_5-15are05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_creator_5-15imh05_firmware AND versionEndExcluding=egcn36ww
OR
vendor=lenovo AND product=ideapad_creator_5-15imh05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_gaming_3-15arh05_firmware AND versionEndExcluding=fccn17ww
OR
vendor=lenovo AND product=ideapad_gaming_3-15arh05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_gaming_3-15imh05_firmware AND versionEndExcluding=egcn36ww
OR
vendor=lenovo AND product=ideapad_gaming_3-15imh05 AND version=-
 

Reference

 


Keywords

NVD

 

CVE-2021-3971

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.