CVE Feed

    Dashboard / CVE / CVE-2017-3754

    CVE-2017-3754

    Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.

    Published:Jul 17, 2017
    Last Modified:Apr 20, 2025
    EPS:Jul 17, 2017
    EPSS Score:0.00043
    CVSS Score:6.7

    Affected Products

    Vendor
    Lenovo
    Product
    710s-13ikb\/xiaoxin Air 13ikb
    Vendor
    Lenovo
    Product
    710s-13isk\/xiaoxin Air 13
    Vendor
    Lenovo
    Product
    Bios
    Vendor
    Lenovo
    Product
    K21-80
    Vendor
    Lenovo
    Product
    K22-80\/lenovo V720-12
    Vendor
    Lenovo
    Product
    K41-80
    Vendor
    Lenovo
    Product
    Lenovo Ideapad 110-14ast
    Vendor
    Lenovo
    Product
    Lenovo Ideapad 110-15ast
    Vendor
    Lenovo
    Product
    Lenovo Ideapad 320-14ast
    Vendor
    Lenovo
    Product
    Lenovo Ideapad 320-15ast
    Vendor
    Lenovo
    Product
    Lenovo Xiaoxin Rui7000
    Vendor
    Lenovo
    Product
    Miix 710-12ikb
    Vendor
    Lenovo
    Product
    Miix 720-12ikb
    Vendor
    Lenovo
    Product
    Notebook 320-17ast
    Vendor
    Lenovo
    Product
    Rescuer E520-15ikb
    Vendor
    Lenovo
    Product
    V110-14iap
    Vendor
    Lenovo
    Product
    V110-15iap
    Vendor
    Lenovo
    Product
    V110-15ikb
    Vendor
    Lenovo
    Product
    V110-15isk
    Vendor
    Lenovo
    Product
    Yoga 710-11ikb

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High