ID

VAR-202006-1800


CVE

CVE-2020-8321


TITLE

plural Lenovo Notebook and ThinkStation Vulnerabilities in the model

Trust: 0.8

sources: JVNDB: JVNDB-2020-006844

DESCRIPTION

A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. plural Lenovo Notebook and ThinkStation There are unspecified vulnerabilities in the model.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state

Trust: 1.62

sources: NVD: CVE-2020-8321 // JVNDB: JVNDB-2020-006844

AFFECTED PRODUCTS

vendor:lenovomodel:yoga 530-14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p520scope:ltversion:2020-09-01

Trust: 1.0

vendor:lenovomodel:xiaoxin air 15ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v320-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y7000p 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:e43-80 kblscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v320-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:d330-10igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p510scope:ltversion:s00kya7a

Trust: 1.0

vendor:lenovomodel:330-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15ichscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-14iilscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:530s-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v130-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15arr touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y7000 pg0scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-15imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:130-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-17ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:zhaoyang k42-80scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:130-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-15apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:y7000 2019 1050scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:720s-13arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330c-15ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y540-15irhscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xx-14kb qc 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:flex 6-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y545scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v720-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-14iskscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p920scope:ltversion:2020-09-01

Trust: 1.0

vendor:lenovomodel:530s-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v145-14astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:530s-14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-15iilscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p520cscope:ltversion:2020-09-01

Trust: 1.0

vendor:lenovomodel:ideapad 5 15iil05scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-15iwl gtxscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-15imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:wei5-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p910scope:ltversion:s02kt67a

Trust: 1.0

vendor:lenovomodel:s530-13iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin-14iwl qc 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideapad 3 17iml05scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v130-14igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y740-17ichgscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:320c-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-15astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air-15iwl 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:flex-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:e41-25scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-15irhscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-14scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-15apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y540-17 pg0scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y530-15ich-1060scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-14igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:340c-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v130-14astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air 15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y730-17ichscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-15igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y740-17irhgscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-15api touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-17ichscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:130-14astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-15iwl touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y7000p-1060scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p410scope:ltversion:s00kya7a

Trust: 1.0

vendor:lenovomodel:thinkstation p710scope:ltversion:s01kt67a

Trust: 1.0

vendor:lenovomodel:s540-14imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-14apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-14imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideapad 3 15iil05scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v145-15astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-17apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:340c-15igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:rescuer y7000pscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-14apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p500scope:ltversion:a4kt67a

Trust: 1.0

vendor:lenovomodel:l340-15iwl touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 730-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air 14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin-13imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v130-15astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y540-17irhscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-17ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l3 15iml05scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:530s-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air-14iwl 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y530-15ichscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15ikbr touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-14ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:flex-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:rescuer y7000\scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga c740-15imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-14imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:flex 6-1470scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin-14 2019iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:130-15astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:e4-14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:k43c-80scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideapad 3 14scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 720-12ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 530-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v320-17ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-15imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y7000p pg0scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-14iwl touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin-15 2019iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 730-13iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p720scope:ltversion:2020-09-01

Trust: 1.0

vendor:lenovomodel:s530-13imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga c940scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air 13iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:720s-14ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideapad 3 15scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air 14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-13imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga c930-13ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air 14ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga c930 glassscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin-14igm qc 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:flex 6-14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v320-17ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y545 pg0scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-14scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y540-15 pg0scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:530s-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-14igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-17iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y7000 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y730-15ichscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 730-13ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-14apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-14iwl touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga c740-14imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330c-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:d335-10igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:340c-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y9000p 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y9000k 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330c-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-17irhscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p900scope:ltversion:a6kta7a

Trust: 1.0

vendor:lenovomodel:s145-14igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y740-15irhgscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y740-15ichgscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:rescuer y7000scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-14astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideapad 3 14iil05scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:rescuer y7000p\scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p700scope:ltversion:a5kta7a

Trust: 1.0

vendor:lenovomodel:yoga s740-14iilscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s550-14iilscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 730-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:130-14astscope: - version: -

Trust: 0.8

vendor:lenovomodel:130-14ikbscope: - version: -

Trust: 0.8

vendor:lenovomodel:130-15astscope: - version: -

Trust: 0.8

vendor:lenovomodel:130-15ikbscope: - version: -

Trust: 0.8

vendor:lenovomodel:320c-15ikbscope: - version: -

Trust: 0.8

vendor:lenovomodel:330-14igmscope: - version: -

Trust: 0.8

vendor:lenovomodel:330-14ikbscope: - version: -

Trust: 0.8

vendor:lenovomodel:330-14ikbrscope: - version: -

Trust: 0.8

vendor:lenovomodel:330-15arrscope: - version: -

Trust: 0.8

vendor:lenovomodel:330-15arr touchscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-006844 // NVD: CVE-2020-8321

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-8321
value: MEDIUM

Trust: 1.0

psirt@lenovo.com: CVE-2020-8321
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-006844
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202006-806
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-8321
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-006844
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2020-8321
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.1

Trust: 1.0

psirt@lenovo.com: CVE-2020-8321
baseSeverity: MEDIUM
baseScore: 6.4
vectorString: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.5
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-006844
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-006844 // CNNVD: CNNVD-202006-806 // NVD: CVE-2020-8321 // NVD: CVE-2020-8321

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2020-8321

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202006-806

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202006-806

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-006844

PATCH

title:LEN-30042url:https://support.lenovo.com/us/en/product_security/LEN-30042

Trust: 0.8

sources: JVNDB: JVNDB-2020-006844

EXTERNAL IDS

db:NVDid:CVE-2020-8321

Trust: 2.4

db:LENOVOid:LEN-30042

Trust: 1.6

db:JVNDBid:JVNDB-2020-006844

Trust: 0.8

db:CNNVDid:CNNVD-202006-806

Trust: 0.6

sources: JVNDB: JVNDB-2020-006844 // CNNVD: CNNVD-202006-806 // NVD: CVE-2020-8321

REFERENCES

url:https://support.lenovo.com/us/en/product_security/len-30042

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-8321

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-8321

Trust: 0.8

sources: JVNDB: JVNDB-2020-006844 // CNNVD: CNNVD-202006-806 // NVD: CVE-2020-8321

CREDITS

MengHao,yngwei (@yngweijw),Li of IIE VARAS,driedfish (@d3af1sh)

Trust: 0.6

sources: CNNVD: CNNVD-202006-806

SOURCES

db:JVNDBid:JVNDB-2020-006844
db:CNNVDid:CNNVD-202006-806
db:NVDid:CVE-2020-8321

LAST UPDATE DATE

2024-08-14T13:11:39.453000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-006844date:2020-07-20T00:00:00
db:CNNVDid:CNNVD-202006-806date:2020-06-30T00:00:00
db:NVDid:CVE-2020-8321date:2020-06-22T13:37:04.390

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-006844date:2020-07-20T00:00:00
db:CNNVDid:CNNVD-202006-806date:2020-06-09T00:00:00
db:NVDid:CVE-2020-8321date:2020-06-09T20:15:22.240