ID

VAR-201904-0088


CVE

CVE-2019-6156


TITLE

Lenovo Vulnerabilities related to security functions in the system

Trust: 0.8

sources: JVNDB: JVNDB-2019-003417

DESCRIPTION

In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected. Lenovo There are vulnerabilities related to security functions in the system.Information may be tampered with. Lenovo 510-15IKL and others are all desktop computers produced by China Lenovo (Lenovo). This vulnerability is due to the lack of security measures such as authentication, access control, and rights management in network systems or products. The following products are affected: Lenovo 510-15IKL; 510S-08IKL; IdeaCentre 300-20ISH; IdeaCentre 300S-11ISH; IdeaCentre 510-15ICB;

Trust: 1.71

sources: NVD: CVE-2019-6156 // JVNDB: JVNDB-2019-003417 // VULHUB: VHN-157591

AFFECTED PRODUCTS

vendor:lenovomodel:thinkcentre m83 \scope:ltversion:fbktd5a

Trust: 3.0

vendor:lenovomodel:thinkcentre m93p \scope:ltversion:fbktd5a

Trust: 2.0

vendor:lenovomodel:thinkcentre m73 \scope:eqversion: -

Trust: 2.0

vendor:lenovomodel:thinkcentre e93 \scope:ltversion:fbktd5a

Trust: 2.0

vendor:lenovomodel:thinkcentre e73 \scope:eqversion: -

Trust: 2.0

vendor:lenovomodel:yangtian mc h81scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m818zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m73 tinyscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p300scope:ltversion:fbktd5a

Trust: 1.0

vendor:lenovomodel:530s-07icbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:qitian m4650scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m800scope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:yangtian mc h110 pciscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m9550zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p900scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yangtian mf\/wf h110 pciscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideacentre 300s-11ishscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m7300zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre e73sscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yangtian mf\/wf h81 pciscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p318scope:ltversion:m1akt3fa

Trust: 1.0

vendor:lenovomodel:thinkstation p710scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m920zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m920xscope:ltversion:m1ukt33a

Trust: 1.0

vendor:lenovomodel:v520s-08iklscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:qitian m4600scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m4500qscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m900scope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:thinkpad x260scope:ltversion:r02et70w

Trust: 1.0

vendor:lenovomodel:qt b415scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600qscope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:510s-08iklscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideacentre 300-20ishscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation e32scope:ltversion:fbktd5a

Trust: 1.0

vendor:lenovomodel:thinkcentre m93scope:ltversion:fbktd5a

Trust: 1.0

vendor:lenovomodel:ideacentre 620s-03iklscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v530-24icb\scope:ltversion:m20kt38a

Trust: 1.0

vendor:lenovomodel:thinkcentre m900zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v520t-15iklscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:63scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m8500sscope:ltversion:fbktd5a

Trust: 1.0

vendor:lenovomodel:legion t530-28icbscope:ltversion:o3lkt20a

Trust: 1.0

vendor:lenovomodel:yangtian ytm6900e-00scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion c730-19icoscope:ltversion:o3nkt20a

Trust: 1.0

vendor:lenovomodel:yangtian mc h110scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p510scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:m4550 idscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v510z \scope:ltversion:m1dkt26a

Trust: 1.0

vendor:lenovomodel:thinkstation p500scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion c530-19icbscope:ltversion:o3lkt20a

Trust: 1.0

vendor:lenovomodel:thinkcentre e74zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m93p tinyscope:ltversion:fbktd5a

Trust: 1.0

vendor:lenovomodel:thinkcentre m720tscope:lteversion:m1ukt33a

Trust: 1.0

vendor:lenovomodel:aio520-24ikuscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m820zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m9500zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre e75tscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m8600sscope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:thinkcentre m710qscope:ltversion:m1akt3fa

Trust: 1.0

vendor:lenovomodel:thinkcentre e74sscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yangtian afq150scope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:thinkcentre m920qscope:ltversion:m1ukt33a

Trust: 1.0

vendor:lenovomodel:thinkcentre m73pscope:ltversion:fbktd5a

Trust: 1.0

vendor:lenovomodel:thinkstation c30 refreshscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m700zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m920tscope:ltversion:m1ukt33a

Trust: 1.0

vendor:lenovomodel:thinkcentre m920sscope:ltversion:m1ukt33a

Trust: 1.0

vendor:lenovomodel:yangtian afh110scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yangtian ms\/ws h81scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:qt m415scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m910xscope:ltversion:m1akt3fa

Trust: 1.0

vendor:lenovomodel:thinkstation p520cscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m6500tscope:ltversion:fbktd5a

Trust: 1.0

vendor:lenovomodel:thinkcentre m910sscope:ltversion:m1akt3fa

Trust: 1.0

vendor:lenovomodel:thinkcentre m83z \scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation s30 refreshscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad s5scope:ltversion:r09et70w

Trust: 1.0

vendor:lenovomodel:ideacentre 730s-24ikbscope:ltversion:o3wkt15a

Trust: 1.0

vendor:lenovomodel:aio520-22ikuscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m8300zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v530-22icb\scope:ltversion:m20kt38a

Trust: 1.0

vendor:lenovomodel:thinkpad e580scope:ltversion:r0pet54w

Trust: 1.0

vendor:lenovomodel:thinkpad t460scope:ltversion:r06et66w

Trust: 1.0

vendor:lenovomodel:thinkcentre e96zscope:ltversion:m26kt11a

Trust: 1.0

vendor:lenovomodel:510-15iklscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio520-27iklscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yta8900fscope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:m4500 idscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yangtian me\/we h110scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad l580scope:ltversion:r0qet54w

Trust: 1.0

vendor:lenovomodel:thinkstation p320scope:ltversion:s06kt40a

Trust: 1.0

vendor:lenovomodel:thinkcentre m8600tscope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:ideacentre 700scope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:thinkcentre m700sscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m910tscope:ltversion:m1akt3fa

Trust: 1.0

vendor:lenovomodel:thinkstation p910scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad t460pscope:ltversion:r07et88w

Trust: 1.0

vendor:lenovomodel:thinkcentre m710sscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m720sscope:ltversion:m1ukt33a

Trust: 1.0

vendor:lenovomodel:thinkcentre m800zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e480scope:ltversion:r0pet54w

Trust: 1.0

vendor:lenovomodel:qitian m4550scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m4500kscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m6500sscope:ltversion:fbktd5a

Trust: 1.0

vendor:lenovomodel:thinkpad x380 yogascope:ltversion:r0set42w

Trust: 1.0

vendor:lenovomodel:thinkcentre m910zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p330scope:ltversion:m1vkt34a

Trust: 1.0

vendor:lenovomodel:ideacentre 510s-08ishscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcenter m700zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p520scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p920scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation d30 refreshscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600tscope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:thinkcentre x1 aioscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideacentre 520s-23ikuscope:ltversion:o34kt23a

Trust: 1.0

vendor:lenovomodel:thinkcentre m700tscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m700qscope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:thinkstation p330 tinyscope:ltversion:m1ukt33a

Trust: 1.0

vendor:lenovomodel:thinkcentre m720qscope:ltversion:m1ukt33a

Trust: 1.0

vendor:lenovomodel:thinkcentre m910qscope:ltversion:m1akt3fa

Trust: 1.0

vendor:lenovomodel:qt a7400scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p720scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre e74scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e560pscope:ltversion:r09et70w

Trust: 1.0

vendor:lenovomodel:ideacentre 510-15icbscope:ltversion:o3qkt32a

Trust: 1.0

vendor:lenovomodel:thinkcentre m4500sscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yangtian afh81scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y720 towerscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15igmscope:ltversion:7xcn30ww

Trust: 1.0

vendor:lenovomodel:qitian b4650scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideacentre 510a-15icbscope:ltversion:o3qkt32a

Trust: 1.0

vendor:lenovomodel:thinkcentre e75sscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600scope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:qitian 4500scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio y910-27ishscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v310z\scope:ltversion:m18kt25a

Trust: 1.0

vendor:lenovomodel:thinkcentre m8350zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio520-22iklscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio520-24iklscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion t730-28icoscope:ltversion:o3nkt20a

Trust: 1.0

vendor:lenovomodel:thinkcentre s510scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:qitian b4550scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcenter m800zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y520t z370scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y920 towerscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio300-23isu\scope:ltversion:o1lkt46a

Trust: 1.0

vendor:lenovomodel:qt m410scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p700scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p310scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m710tscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e570pscope:ltversion:r0met46w

Trust: 1.0

vendor:lenovomodel:thinkpad l480scope:ltversion:r0qet54w

Trust: 1.0

vendor:lenovomodel:thinkcentre e95zscope:ltversion:m1lkt20a

Trust: 1.0

vendor:lenovomodel:v410z\scope:ltversion:m17kt41a

Trust: 1.0

vendor:lenovomodel:thinkpad s5scope:ltversion:r0met46w

Trust: 1.0

vendor:lenovomodel:h50-30g desktopscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideacentre 720-18icbscope:ltversion:o3qkt32a

Trust: 1.0

vendor:lenovomodel:thinkcentre m4500tscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m610scope:ltversion:m1akt3fa

Trust: 1.0

vendor:lenovomodel:yangtian tc\/wcc h81 pciscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p320 tinyscope:ltversion:m1akt3fa

Trust: 1.0

vendor:lenovomodel:thinkstation p410scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yangtian tc\/wc h110 pciscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600sscope:ltversion:fwkt9aa

Trust: 1.0

vendor:lenovomodel:thinkcentre m710escope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-14igmscope:ltversion:7xcn30ww

Trust: 1.0

vendor:lenovomodel:thinkcentre m4600tscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m810zscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m4600sscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio 910-27ishscope:ltversion:o37kt13a

Trust: 1.0

vendor:lenovomodel:m4500scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m8500tscope:ltversion:fbktd5a

Trust: 1.0

vendor:lenovomodel:510-15iklscope: - version: -

Trust: 0.8

vendor:lenovomodel:510s-08iklscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 300-20ishscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 300s-11ishscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 510-15icbscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 510a-15icbscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 510s-08ishscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 620s-03iklscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 700scope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 720-18icbscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2019-003417 // NVD: CVE-2019-6156

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-6156
value: LOW

Trust: 1.0

NVD: CVE-2019-6156
value: LOW

Trust: 0.8

CNNVD: CNNVD-201904-304
value: LOW

Trust: 0.6

VULHUB: VHN-157591
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2019-6156
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-157591
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-6156
baseSeverity: LOW
baseScore: 3.3
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 1.4
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-157591 // JVNDB: JVNDB-2019-003417 // CNNVD: CNNVD-201904-304 // NVD: CVE-2019-6156

PROBLEMTYPE DATA

problemtype:CWE-667

Trust: 1.1

problemtype:CWE-254

Trust: 0.9

sources: VULHUB: VHN-157591 // JVNDB: JVNDB-2019-003417 // NVD: CVE-2019-6156

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201904-304

TYPE

security feature problem

Trust: 0.6

sources: CNNVD: CNNVD-201904-304

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-003417

PATCH

title:LEN-26332url:https://support.lenovo.com/solutions/LEN-26332

Trust: 0.8

title:Multiple Lenovo Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=91143

Trust: 0.6

sources: JVNDB: JVNDB-2019-003417 // CNNVD: CNNVD-201904-304

EXTERNAL IDS

db:NVDid:CVE-2019-6156

Trust: 2.5

db:LENOVOid:LEN-26332

Trust: 1.7

db:JVNDBid:JVNDB-2019-003417

Trust: 0.8

db:CNNVDid:CNNVD-201904-304

Trust: 0.7

db:VULHUBid:VHN-157591

Trust: 0.1

sources: VULHUB: VHN-157591 // JVNDB: JVNDB-2019-003417 // CNNVD: CNNVD-201904-304 // NVD: CVE-2019-6156

REFERENCES

url:https://support.lenovo.com/solutions/len-26332

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2019-6156

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-6156

Trust: 0.8

url:https://support.lenovo.com/us/en/product_security/len-26332

Trust: 0.6

sources: VULHUB: VHN-157591 // JVNDB: JVNDB-2019-003417 // CNNVD: CNNVD-201904-304 // NVD: CVE-2019-6156

SOURCES

db:VULHUBid:VHN-157591
db:JVNDBid:JVNDB-2019-003417
db:CNNVDid:CNNVD-201904-304
db:NVDid:CVE-2019-6156

LAST UPDATE DATE

2024-11-23T22:37:53.947000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-157591date:2020-08-24T00:00:00
db:JVNDBid:JVNDB-2019-003417date:2019-05-16T00:00:00
db:CNNVDid:CNNVD-201904-304date:2020-08-25T00:00:00
db:NVDid:CVE-2019-6156date:2024-11-21T04:46:02.577

SOURCES RELEASE DATE

db:VULHUBid:VHN-157591date:2019-04-10T00:00:00
db:JVNDBid:JVNDB-2019-003417date:2019-05-16T00:00:00
db:CNNVDid:CNNVD-201904-304date:2019-04-04T00:00:00
db:NVDid:CVE-2019-6156date:2019-04-10T17:29:00.463