ID

VAR-201609-0686


TITLE

A variety of Lenovo product SSD firmware information disclosure vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-07048

DESCRIPTION

An information disclosure vulnerability exists in several Lenovo product SSD firmware. An attacker can exploit the vulnerability to gain sensitive information, which could lead to further attacks. Multiple Lenovo products are prone to a local information-disclosure vulnerability

Trust: 0.81

sources: CNVD: CNVD-2016-07048 // BID: 92178

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-07048

AFFECTED PRODUCTS

vendor:lenovomodel:thinkstation s30scope:eqversion:0

Trust: 0.9

vendor:lenovomodel:thinkstation p310scope:eqversion:0

Trust: 0.9

vendor:lenovomodel:thinkstation p900scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkstation e32scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkstation d30scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkstation c30scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad yogascope:eqversion:140

Trust: 0.3

vendor:lenovomodel:thinkpad yogascope:eqversion:120

Trust: 0.3

vendor:lenovomodel:thinkpad yoga 11escope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpadscope:eqversion:x2500

Trust: 0.3

vendor:lenovomodel:thinkpad x240sscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpadscope:eqversion:x2400

Trust: 0.3

vendor:lenovomodel:thinkpadscope:eqversion:x1310

Trust: 0.3

vendor:lenovomodel:thinkpad w550sscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad w540scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t550scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t540pscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t450sscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t450scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t440sscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t440pscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad t440scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad s540scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad s5 yogascope:eqversion:150

Trust: 0.3

vendor:lenovomodel:thinkpad s440scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad s1 yogascope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad l540scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad l450scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad l440scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad e555scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad e550scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad e540scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad e455scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad e450scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad e440scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad m93zscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad m83zscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad m79scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad m73zscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad m73pscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad e93zscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkpad e79scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkcentre m93scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkcentre m83scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkcentre m73scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkcentre m53scope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkcentre e73zscope:eqversion:0

Trust: 0.3

vendor:lenovomodel:thinkstation s30scope:neversion:01

Trust: 0.3

vendor:lenovomodel:thinkstation p700scope:neversion:01

Trust: 0.3

vendor:lenovomodel:thinkstation p500scope:neversion:01

Trust: 0.3

vendor:lenovomodel:thinkstation p300scope:neversion:01

Trust: 0.3

vendor:lenovomodel:thinkstation e32scope:neversion:01

Trust: 0.3

vendor:lenovomodel:thinkstation d30scope:neversion:01

Trust: 0.3

vendor:lenovomodel:thinkstation c30scope:neversion:01

Trust: 0.3

vendor:lenovomodel:thinkpadscope:neversion:x13101

Trust: 0.3

vendor:lenovomodel:thinkpad carbonscope:neversion:x12.74

Trust: 0.3

sources: CNVD: CNVD-2016-07048 // BID: 92178

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-07048
value: LOW

Trust: 0.6

CNVD: CNVD-2016-07048
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-07048

THREAT TYPE

local

Trust: 0.3

sources: BID: 92178

TYPE

Design Error

Trust: 0.3

sources: BID: 92178

PATCH

title:Patches for several Lenovo product SSD firmware information disclosure vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/81013

Trust: 0.6

sources: CNVD: CNVD-2016-07048

EXTERNAL IDS

db:BIDid:92178

Trust: 0.9

db:CNVDid:CNVD-2016-07048

Trust: 0.6

sources: CNVD: CNVD-2016-07048 // BID: 92178

REFERENCES

url:http://www.securityfocus.com/bid/92178

Trust: 0.6

url:https://support.lenovo.com/us/zh/product_security/len_5595

Trust: 0.6

url:http://www.lenovo.com/ca/en/

Trust: 0.3

url:https://support.lenovo.com/us/en/product_security/len_5595

Trust: 0.3

sources: CNVD: CNVD-2016-07048 // BID: 92178

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 92178

SOURCES

db:CNVDid:CNVD-2016-07048
db:BIDid:92178

LAST UPDATE DATE

2022-05-17T01:52:38.252000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-07048date:2016-09-01T00:00:00
db:BIDid:92178date:2016-07-28T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-07048date:2016-09-01T00:00:00
db:BIDid:92178date:2016-07-28T00:00:00