CVE Feed

    Dashboard / CVE / CVE-2021-3719

    CVE-2021-3719

    A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.

    Published:Nov 12, 2021
    Last Modified:Nov 21, 2024
    EPS:Nov 12, 2021
    EPSS Score:0.00037
    CVSS Score:6.7

    Affected Products

    Vendor
    Lenovo
    Product
    Thinkcentre E93
    Vendor
    Lenovo
    Product
    Thinkcentre E93 Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M4500q
    Vendor
    Lenovo
    Product
    Thinkcentre M4500q Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M600
    Vendor
    Lenovo
    Product
    Thinkcentre M600 Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M6500t\/s
    Vendor
    Lenovo
    Product
    Thinkcentre M6500t\/s Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M700 Tiny
    Vendor
    Lenovo
    Product
    Thinkcentre M700 Tiny Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M73
    Vendor
    Lenovo
    Product
    Thinkcentre M73 Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M73p
    Vendor
    Lenovo
    Product
    Thinkcentre M73p Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M800
    Vendor
    Lenovo
    Product
    Thinkcentre M800 Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M818z
    Vendor
    Lenovo
    Product
    Thinkcentre M818z Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M83
    Vendor
    Lenovo
    Product
    Thinkcentre M83 Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M8500t\/s
    Vendor
    Lenovo
    Product
    Thinkcentre M8500t\/s Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M900
    Vendor
    Lenovo
    Product
    Thinkcentre M900 Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M900x
    Vendor
    Lenovo
    Product
    Thinkcentre M900x Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M93
    Vendor
    Lenovo
    Product
    Thinkcentre M93 Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre M93p
    Vendor
    Lenovo
    Product
    Thinkcentre M93p Firmware
    Vendor
    Lenovo
    Product
    Thinkcentre X1
    Vendor
    Lenovo
    Product
    Thinkcentre X1 Firmware
    Vendor
    Lenovo
    Product
    Thinkstation P300
    Vendor
    Lenovo
    Product
    Thinkstation P300 Firmware
    Vendor
    Lenovo
    Product
    Thinkstation P500
    Vendor
    Lenovo
    Product
    Thinkstation P500 Firmware
    Vendor
    Lenovo
    Product
    Thinkstation P700
    Vendor
    Lenovo
    Product
    Thinkstation P700 Firmware
    Vendor
    Lenovo
    Product
    Thinkstation P900
    Vendor
    Lenovo
    Product
    Thinkstation P900 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High