Versio.io

CVE-2021-3972

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 22-04-2022 11:15
Last modified: - 06-05-2022 10:49
Total changes: - 3

Description

A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Low
Attack complexity
Local
Attack vector
High
Availability
High
Confidentiality
High
Integrity
High
Privileges required
Unchanged
Scope
None
User interaction
6.7
Base score
0.8
5.9
Exploitability score
Impact score
 

Verification logic

OR
AND
OR
vendor=lenovo AND product=ideapad_3-14ada05_firmware AND versionEndExcluding=e8cn33ww
OR
vendor=lenovo AND product=ideapad_3-14ada05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14ada6_firmware AND versionEndExcluding=hbcn21ww
OR
vendor=lenovo AND product=ideapad_3-14ada6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14alc6_firmware AND versionEndExcluding=glcn43ww
OR
vendor=lenovo AND product=ideapad_3-14alc6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14are05_firmware AND versionEndExcluding=dzcn42ww
OR
vendor=lenovo AND product=ideapad_3-14are05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15ada6_firmware AND versionEndExcluding=hbcn21ww
OR
vendor=lenovo AND product=ideapad_3-15ada6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15alc6_firmware AND versionEndExcluding=glcn43ww
OR
vendor=lenovo AND product=ideapad_3-15alc6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15are05_firmware AND versionEndExcluding=dzcn42ww
OR
vendor=lenovo AND product=ideapad_3-15are05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15igl05_firmware AND versionEndExcluding=dvcn23ww
OR
vendor=lenovo AND product=ideapad_3-15igl05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17ada05_firmware AND versionEndExcluding=e8cn33ww
OR
vendor=lenovo AND product=ideapad_3-17ada05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17ada6_firmware AND versionEndExcluding=hbcn21ww
OR
vendor=lenovo AND product=ideapad_3-17ada6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17alc6_firmware AND versionEndExcluding=glcn43ww
OR
vendor=lenovo AND product=ideapad_3-17alc6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17are05_firmware AND versionEndExcluding=dzcn42ww
OR
vendor=lenovo AND product=ideapad_3-17are05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17iil05_firmware AND versionEndExcluding=emcn52ww
OR
vendor=lenovo AND product=ideapad_3-17iil05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17itl6_firmware AND versionEndExcluding=ggcn33ww
OR
vendor=lenovo AND product=ideapad_3-17itl6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15ada05_firmware AND versionEndExcluding=e8cn33ww
OR
vendor=lenovo AND product=ideapad_3-15ada05 AND version=-
AND
OR
vendor=lenovo AND product=l3_15iml05_firmware AND versionEndExcluding=ejcn27ww
OR
vendor=lenovo AND product=l3_15iml05 AND version=-
AND
OR
vendor=lenovo AND product=l3-15itl6_firmware AND versionEndExcluding=gfcn23ww
OR
vendor=lenovo AND product=l3-15itl6 AND version=-
AND
OR
vendor=lenovo AND product=l340-15irh_firmware AND versionEndExcluding=bgcn35ww
OR
vendor=lenovo AND product=l340-15irh AND version=-
AND
OR
vendor=lenovo AND product=l340-15iwl_firmware AND versionEndExcluding=atcn46ww
OR
vendor=lenovo AND product=l340-15iwl AND version=-
AND
OR
vendor=lenovo AND product=l340-15iwl_touch_firmware AND versionEndExcluding=atcn46ww
OR
vendor=lenovo AND product=l340-15iwl_touch AND version=-
AND
OR
vendor=lenovo AND product=l340-17irh_firmware AND versionEndExcluding=bgcn35ww
OR
vendor=lenovo AND product=l340-17irh AND version=-
AND
OR
vendor=lenovo AND product=l340-17iwl_firmware AND versionEndExcluding=atcn46ww
OR
vendor=lenovo AND product=l340-17iwl AND version=-
AND
OR
vendor=lenovo AND product=legion_5_pro-16ach6_firmware AND versionEndExcluding=hhcn25ww
OR
vendor=lenovo AND product=legion_5_pro-16ach6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5_pro-16ach6h_firmware AND versionEndExcluding=gkcn51ww
OR
vendor=lenovo AND product=legion_5_pro-16ach6h AND version=-
AND
OR
vendor=lenovo AND product=legion_5_pro-16ith6_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5_pro-16ith6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5_pro-16ith6h_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5_pro-16ith6h AND version=-
AND
OR
vendor=lenovo AND product=legion_5-15ach6_firmware AND versionEndExcluding=hhcn25ww
OR
vendor=lenovo AND product=legion_5-15ach6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5-15ach6a_firmware AND versionEndExcluding=g9cn28ww
OR
vendor=lenovo AND product=legion_5-15ach6a AND version=-
AND
OR
vendor=lenovo AND product=legion_5-15ach6h_firmware AND versionEndExcluding=gkcn51ww
OR
vendor=lenovo AND product=legion_5-15ach6h AND version=-
AND
OR
vendor=lenovo AND product=legion_5-15imh6_firmware AND versionEndExcluding=g8cn19ww
OR
vendor=lenovo AND product=legion_5-15imh6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5-15ith6_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5-15ith6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5-15ith6h_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5-15ith6h AND version=-
AND
OR
vendor=lenovo AND product=legion_5-17ach6_firmware AND versionEndExcluding=hhcn25ww
OR
vendor=lenovo AND product=legion_5-17ach6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5-17ach6h_firmware AND versionEndExcluding=gkcn51ww
OR
vendor=lenovo AND product=legion_5-17ach6h AND version=-
AND
OR
vendor=lenovo AND product=legion_5-17ith6_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5-17ith6 AND version=-
AND
OR
vendor=lenovo AND product=legion_5-17ith6h_firmware AND versionEndExcluding=h1cn46ww
OR
vendor=lenovo AND product=legion_5-17ith6h AND version=-
AND
OR
vendor=lenovo AND product=legion_7-16achg6_firmware AND versionEndExcluding=gkcn51ww
OR
vendor=lenovo AND product=legion_7-16achg6 AND version=-
AND
OR
vendor=lenovo AND product=legion_7-16ithg6_firmware AND versionEndExcluding=gkcn51ww
OR
vendor=lenovo AND product=legion_7-16ithg6 AND version=-
AND
OR
vendor=lenovo AND product=legion_s7-15ach6_firmware AND versionEndExcluding=hacn35ww
OR
vendor=lenovo AND product=legion_s7-15ach6 AND version=-
AND
OR
vendor=lenovo AND product=legion_y540-15irh_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y540-15irh AND version=-
AND
OR
vendor=lenovo AND product=legion_y540-15irh-pg0_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y540-15irh-pg0 AND version=-
AND
OR
vendor=lenovo AND product=legion_y540-17irh_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y540-17irh AND version=-
AND
OR
vendor=lenovo AND product=legion_y540-17irh-pg0_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y540-17irh-pg0 AND version=-
AND
OR
vendor=lenovo AND product=legion_y545_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y545 AND version=-
AND
OR
vendor=lenovo AND product=legion_y545-pg0_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y545-pg0 AND version=-
AND
OR
vendor=lenovo AND product=legion_y7000-2019_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y7000-2019 AND version=-
AND
OR
vendor=lenovo AND product=legion_y7000-2019-pg0_firmware AND versionEndExcluding=bhcn44ww
OR
vendor=lenovo AND product=legion_y7000-2019-pg0 AND version=-
AND
OR
vendor=lenovo AND product=s14_g2_itl_firmware AND versionEndExcluding=ggcn33ww
OR
vendor=lenovo AND product=s14_g2_itl AND version=-
AND
OR
vendor=lenovo AND product=s145-14api_firmware AND versionEndExcluding=bucn31ww
OR
vendor=lenovo AND product=s145-14api AND version=-
AND
OR
vendor=lenovo AND product=s145-14ast_firmware AND versionEndExcluding=aycn26ww
OR
vendor=lenovo AND product=s145-14ast AND version=-
AND
OR
vendor=lenovo AND product=s145-14igm_firmware AND versionEndExcluding=awcn28ww
OR
vendor=lenovo AND product=s145-14igm AND version=-
AND
OR
vendor=lenovo AND product=s145-14iil_firmware AND versionEndExcluding=dkcn54ww
OR
vendor=lenovo AND product=s145-14iil AND version=-
AND
OR
vendor=lenovo AND product=s145-15api_firmware AND versionEndExcluding=bucn31ww
OR
vendor=lenovo AND product=s145-15api AND version=-
AND
OR
vendor=lenovo AND product=s145-15ast_firmware AND versionEndExcluding=aycn26ww
OR
vendor=lenovo AND product=s145-15ast AND version=-
AND
OR
vendor=lenovo AND product=s145-15igm_firmware AND versionEndExcluding=awcn28ww
OR
vendor=lenovo AND product=s145-15igm AND version=-
AND
OR
vendor=lenovo AND product=s145-15iil_firmware AND versionEndExcluding=dkcn54ww
OR
vendor=lenovo AND product=s145-15iil AND version=-
AND
OR
vendor=lenovo AND product=s540-13api_firmware AND versionEndExcluding=cxcn34ww
OR
vendor=lenovo AND product=s540-13api AND version=-
AND
OR
vendor=lenovo AND product=s540-13iml_firmware AND version=-
OR
vendor=lenovo AND product=s540-13iml AND version=-
AND
OR
vendor=lenovo AND product=slim_7_pro-14ihu5_firmware AND version=-
OR
vendor=lenovo AND product=slim_7_pro-14ihu5 AND version=-
AND
OR
vendor=lenovo AND product=slim_9-14itl05_firmware AND version=-
OR
vendor=lenovo AND product=slim_9-14itl05 AND version=-
AND
OR
vendor=lenovo AND product=v14_g1-iml_firmware AND versionEndExcluding=dxcn41ww
OR
vendor=lenovo AND product=v14_g1-iml AND version=-
AND
OR
vendor=lenovo AND product=v14_g2-acl_firmware AND versionEndExcluding=glcn43ww
OR
vendor=lenovo AND product=v14_g2-acl AND version=-
AND
OR
vendor=lenovo AND product=v14_g2-itl_firmware AND versionEndExcluding=ggcn33ww
OR
vendor=lenovo AND product=v14_g2-itl AND version=-
AND
OR
vendor=lenovo AND product=v14-ada_firmware AND versionEndExcluding=e8cn33ww
OR
vendor=lenovo AND product=v14-ada AND version=-
AND
OR
vendor=lenovo AND product=v14-are_firmware AND versionEndExcluding=dzcn42ww
OR
vendor=lenovo AND product=v14-are AND version=-
AND
OR
vendor=lenovo AND product=v14-igl_firmware AND versionEndExcluding=dvcn23ww
OR
vendor=lenovo AND product=v14-igl AND version=-
AND
OR
vendor=lenovo AND product=v14-iil_firmware AND versionEndExcluding=dkcn54ww
OR
vendor=lenovo AND product=v14-iil AND version=-
AND
OR
vendor=lenovo AND product=v140-15iwl_firmware AND versionEndExcluding=atcn46ww
OR
vendor=lenovo AND product=v140-15iwl AND version=-
AND
OR
vendor=lenovo AND product=v15_g1-iml_firmware AND versionEndExcluding=dxcn41ww
OR
vendor=lenovo AND product=v15_g1-iml AND version=-
AND
OR
vendor=lenovo AND product=v15_g2-alc_firmware AND versionEndExcluding=glcn43ww
OR
vendor=lenovo AND product=v15_g2-alc AND version=-
AND
OR
vendor=lenovo AND product=v15_g2-itl_firmware AND versionEndExcluding=ggcn33ww
OR
vendor=lenovo AND product=v15_g2-itl AND version=-
AND
OR
vendor=lenovo AND product=v15-ada_firmware AND versionEndExcluding=e8cn33ww
OR
vendor=lenovo AND product=v15-ada AND version=-
AND
OR
vendor=lenovo AND product=v15-igl_firmware AND versionEndExcluding=dvcn23ww
OR
vendor=lenovo AND product=v15-igl AND version=-
AND
OR
vendor=lenovo AND product=v15-iil_firmware AND versionEndExcluding=dkcn54ww
OR
vendor=lenovo AND product=v15-iil AND version=-
AND
OR
vendor=lenovo AND product=v17_g2-itl_firmware AND versionEndExcluding=ggcn33ww
OR
vendor=lenovo AND product=v17_g2-itl AND version=-
AND
OR
vendor=lenovo AND product=v17-iil_firmware AND versionEndExcluding=emcn52ww
OR
vendor=lenovo AND product=v17-iil AND version=-
AND
OR
vendor=lenovo AND product=v340-17iwl_firmware AND versionEndExcluding=atcn46ww
OR
vendor=lenovo AND product=v340-17iwl AND version=-
AND
OR
vendor=lenovo AND product=yoga_7-14acn6_firmware AND versionEndExcluding=h9cn26ww
OR
vendor=lenovo AND product=yoga_7-14acn6 AND version=-
AND
OR
vendor=lenovo AND product=yoga_c740-14iml_firmware AND versionEndExcluding=bncn44ww
OR
vendor=lenovo AND product=yoga_c740-14iml AND version=-
AND
OR
vendor=lenovo AND product=yoga_c740-15iml_firmware AND versionEndExcluding=bncn44ww
OR
vendor=lenovo AND product=yoga_c740-15iml AND version=-
AND
OR
vendor=lenovo AND product=yoga_c940-14iil_firmware AND version=-
OR
vendor=lenovo AND product=yoga_c940-14iil AND version=-
AND
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5_d_firmware AND versionEndExcluding=hecn24ww
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5_d AND version=-
AND
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5_firmware AND versionEndExcluding=gzcn27ww
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5 AND version=-
AND
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5_o_firmware AND versionEndExcluding=gzcn27ww
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5_o AND version=-
AND
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5_od_firmware AND versionEndExcluding=hecn24ww
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ach5_od AND version=-
AND
OR
vendor=lenovo AND product=yoga_slim_7_pro-14arh5_firmware AND versionEndExcluding=g7cn21ww
OR
vendor=lenovo AND product=yoga_slim_7_pro-14arh5 AND version=-
AND
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ihu5_firmware AND version=-
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ihu5 AND version=-
AND
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ihu5_o_firmware AND version=-
OR
vendor=lenovo AND product=yoga_slim_7_pro-14ihu5_o AND version=-
AND
OR
vendor=lenovo AND product=yoga_slim_7_pro-14itl5_firmware AND version=-
OR
vendor=lenovo AND product=yoga_slim_7_pro-14itl5 AND version=-
AND
OR
vendor=lenovo AND product=yoga_slim_9-14itl05_firmware AND version=-
OR
vendor=lenovo AND product=yoga_slim_9-14itl05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14iil05_firmware AND versionEndExcluding=dvcn23ww
OR
vendor=lenovo AND product=ideapad_3-14iil05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14igl05_firmware AND versionEndExcluding=emcn52ww
OR
vendor=lenovo AND product=ideapad_3-14igl05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14iml05_firmware AND versionEndExcluding=dxcn41ww
OR
vendor=lenovo AND product=ideapad_3-14iml05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14itl05_firmware AND versionEndExcluding=gccn26ww
OR
vendor=lenovo AND product=ideapad_3-14itl05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-14itl6_firmware AND versionEndExcluding=ggcn33ww
OR
vendor=lenovo AND product=ideapad_3-14itl6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15iil05_firmware AND versionEndExcluding=emcn52ww
OR
vendor=lenovo AND product=ideapad_3-15iil05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15iml05_firmware AND versionEndExcluding=dxcn41ww
OR
vendor=lenovo AND product=ideapad_3-15iml05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15itl05_firmware AND versionEndExcluding=gccn26ww
OR
vendor=lenovo AND product=ideapad_3-15itl05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-15itl6_firmware AND versionEndExcluding=ggcn33ww
OR
vendor=lenovo AND product=ideapad_3-15itl6 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_3-17iml05_firmware AND versionEndExcluding=dxcn41ww
OR
vendor=lenovo AND product=ideapad_3-17iml05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_5-15are05_firmware AND versionEndExcluding=e7cn44ww
OR
vendor=lenovo AND product=ideapad_5-15are05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_5-15iil05_firmware AND versionEndExcluding=dpcn54ww
OR
vendor=lenovo AND product=ideapad_5-15iil05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_creator_5-15imh05_firmware AND versionEndExcluding=egcn36ww
OR
vendor=lenovo AND product=ideapad_creator_5-15imh05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_gaming_3-15arh05_firmware AND versionEndExcluding=fccn17ww
OR
vendor=lenovo AND product=ideapad_gaming_3-15arh05 AND version=-
AND
OR
vendor=lenovo AND product=ideapad_gaming_3-15imh05_firmware AND versionEndExcluding=egcn36ww
OR
vendor=lenovo AND product=ideapad_gaming_3-15imh05 AND version=-
 

Reference

 


Keywords

NVD

 

CVE-2021-3972

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.