CVE-2020-8341
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
Published:Sep 1, 2020
Last Modified:Nov 21, 2024
EPS:Sep 1, 2020
EPSS Score:0.00058
CVSS Score:2.4
Affected Products
Vendor
Product
Action
Vendor
Lenovo
Product
Thinkpad T490 \(20nx\)
Lenovo
Thinkpad T490 \(20nx\)
Vendor
Lenovo
Product
Thinkpad T490 \(20nx\) Firmware
Lenovo
Thinkpad T490 \(20nx\) Firmware
Vendor
Lenovo
Product
Thinkpad T490 \(20qx\)
Lenovo
Thinkpad T490 \(20qx\)
Vendor
Lenovo
Product
Thinkpad T490 \(20qx\) Firmware
Lenovo
Thinkpad T490 \(20qx\) Firmware
Vendor
Lenovo
Product
Thinkpad T490 \(20rx\)
Lenovo
Thinkpad T490 \(20rx\)
Vendor
Lenovo
Product
Thinkpad T490 \(20rx\) Firmware
Lenovo
Thinkpad T490 \(20rx\) Firmware
Vendor
Lenovo
Product
Thinkpad T490s \(20nx\)
Lenovo
Thinkpad T490s \(20nx\)
Vendor
Lenovo
Product
Thinkpad T490s \(20nx\) Firmware
Lenovo
Thinkpad T490s \(20nx\) Firmware
Vendor
Lenovo
Product
Thinkpad T495 Drift
Lenovo
Thinkpad T495 Drift
Vendor
Lenovo
Product
Thinkpad T495 Drift Firmware
Lenovo
Thinkpad T495 Drift Firmware
Vendor
Lenovo
Product
Thinkpad T590 \(20nx\)
Lenovo
Thinkpad T590 \(20nx\)
Vendor
Lenovo
Product
Thinkpad T590 \(20nx\) Firmware
Lenovo
Thinkpad T590 \(20nx\) Firmware
Vendor
Lenovo
Product
Thinkpad X1 Carbon \(20qx\)
Lenovo
Thinkpad X1 Carbon \(20qx\)
Vendor
Lenovo
Product
Thinkpad X1 Carbon \(20qx\) Firmware
Lenovo
Thinkpad X1 Carbon \(20qx\) Firmware
Vendor
Lenovo
Product
Thinkpad X1 Yoga \(20qx\)
Lenovo
Thinkpad X1 Yoga \(20qx\)
Vendor
Lenovo
Product
Thinkpad X1 Yoga \(20qx\) Firmware
Lenovo
Thinkpad X1 Yoga \(20qx\) Firmware
Vendor
Lenovo
Product
Thinkpad X390 \(20qx\)
Lenovo
Thinkpad X390 \(20qx\)
Vendor
Lenovo
Product
Thinkpad X390 \(20qx\) Firmware
Lenovo
Thinkpad X390 \(20qx\) Firmware
Vendor
Lenovo
Product
Thinkpad X390 \(20sx\)
Lenovo
Thinkpad X390 \(20sx\)
Vendor
Lenovo
Product
Thinkpad X390 \(20sx\) Firmware
Lenovo
Thinkpad X390 \(20sx\) Firmware
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
