ID

VAR-202006-1800


CVE

CVE-2020-8321


TITLE

plural Lenovo Notebook and ThinkStation Vulnerabilities in the model

Trust: 0.8

sources: JVNDB: JVNDB-2020-006844

DESCRIPTION

A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. plural Lenovo Notebook and ThinkStation There are unspecified vulnerabilities in the model.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state

Trust: 1.62

sources: NVD: CVE-2020-8321 // JVNDB: JVNDB-2020-006844

AFFECTED PRODUCTS

vendor:lenovomodel:s340-14iwl touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-15iwl touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330c-15ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y9000k 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330c-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v130-14igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-14imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-15api touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y7000p 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-15imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p410scope:ltversion:s00kya7a

Trust: 1.0

vendor:lenovomodel:s340-14apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:flex-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y740-17irhgscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideapad 3 15iil05scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p900scope:ltversion:a6kta7a

Trust: 1.0

vendor:lenovomodel:thinkstation p700scope:ltversion:a5kta7a

Trust: 1.0

vendor:lenovomodel:530s-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideapad 3 14scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-17irhscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 730-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xx-14kb qc 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v320-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-15iilscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-17ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:k43c-80scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-15imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:rescuer y7000\scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:130-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-17ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y540-15irhscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:130-14astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideapad 5 15iil05scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:flex-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air 13iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air 14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-15igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 730-13ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y7000 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:rescuer y7000scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s530-13imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:340c-15igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air 15ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga c930 glassscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p520cscope:ltversion:2020-09-01

Trust: 1.0

vendor:lenovomodel:thinkstation p920scope:ltversion:2020-09-01

Trust: 1.0

vendor:lenovomodel:v330-15astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v145-15astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:wei5-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-17apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y545 pg0scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air-15iwl 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y545scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-15iwl gtxscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v145-14astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p720scope:ltversion:2020-09-01

Trust: 1.0

vendor:lenovomodel:330-15arr touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-15apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330c-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:130-15astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:720s-14ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga c740-15imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-13imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-14apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v320-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:530s-14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-14scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-17iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:d330-10igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l3 15iml05scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-15imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15ikbr touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y540-15 pg0scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y740-15irhgscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-14ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-14apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-14igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air 14ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y730-17ichscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air-14iwl 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v130-14astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:530s-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga s740-14iilscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y530-15ich-1060scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y9000p 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v130-15astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y740-15ichgscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:e41-25scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:720s-13arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-14scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y530-15ichscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 530-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 730-13iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:d335-10igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y7000p-1060scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:flex 6-1470scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga c940scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin-14iwl qc 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:530s-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin-15 2019iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v720-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-14imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y740-17ichgscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y540-17 pg0scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v130-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v320-17ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:flex 6-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideapad 3 14iil05scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-15iwl touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:340c-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:530s-14iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:y7000 2019 1050scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y730-15ichscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-14iskscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:e4-14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s530-13iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s550-14iilscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:flex 6-14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air 15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin-14 2019iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 530-14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin-13imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y540-17irhscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:zhaoyang k42-80scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p520scope:ltversion:2020-09-01

Trust: 1.0

vendor:lenovomodel:legion y7000p pg0scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideapad 3 15scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-14iilscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s340-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin-14igm qc 2019scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:rescuer y7000p\scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga c930-13ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:legion y7000 pg0scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-14astscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:xiaoxin air 14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v320-17ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s540-14iwl touchscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga c740-14imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:130-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:c340-14imlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:l340-15irhscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:340c-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p910scope:ltversion:s02kt67a

Trust: 1.0

vendor:lenovomodel:330-17ichscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15ichscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 730-15iwlscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideapad 3 17iml05scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p510scope:ltversion:s00kya7a

Trust: 1.0

vendor:lenovomodel:l340-15apiscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p500scope:ltversion:a4kt67a

Trust: 1.0

vendor:lenovomodel:320c-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:s145-14igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-15igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-14arrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:rescuer y7000pscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 720-12ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-14igmscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkstation p710scope:ltversion:s01kt67a

Trust: 1.0

vendor:lenovomodel:e43-80 kblscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:130-14astscope: - version: -

Trust: 0.8

vendor:lenovomodel:130-14ikbscope: - version: -

Trust: 0.8

vendor:lenovomodel:130-15astscope: - version: -

Trust: 0.8

vendor:lenovomodel:130-15ikbscope: - version: -

Trust: 0.8

vendor:lenovomodel:320c-15ikbscope: - version: -

Trust: 0.8

vendor:lenovomodel:330-14igmscope: - version: -

Trust: 0.8

vendor:lenovomodel:330-14ikbscope: - version: -

Trust: 0.8

vendor:lenovomodel:330-14ikbrscope: - version: -

Trust: 0.8

vendor:lenovomodel:330-15arrscope: - version: -

Trust: 0.8

vendor:lenovomodel:330-15arr touchscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-006844 // NVD: CVE-2020-8321

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-8321
value: MEDIUM

Trust: 1.0

psirt@lenovo.com: CVE-2020-8321
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-006844
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202006-806
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-8321
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-006844
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2020-8321
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.1

Trust: 1.0

psirt@lenovo.com: CVE-2020-8321
baseSeverity: MEDIUM
baseScore: 6.4
vectorString: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.5
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-006844
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-006844 // CNNVD: CNNVD-202006-806 // NVD: CVE-2020-8321 // NVD: CVE-2020-8321

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2020-8321

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202006-806

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202006-806

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-006844

PATCH

title:LEN-30042url:https://support.lenovo.com/us/en/product_security/LEN-30042

Trust: 0.8

sources: JVNDB: JVNDB-2020-006844

EXTERNAL IDS

db:NVDid:CVE-2020-8321

Trust: 2.4

db:LENOVOid:LEN-30042

Trust: 1.6

db:JVNDBid:JVNDB-2020-006844

Trust: 0.8

db:CNNVDid:CNNVD-202006-806

Trust: 0.6

sources: JVNDB: JVNDB-2020-006844 // CNNVD: CNNVD-202006-806 // NVD: CVE-2020-8321

REFERENCES

url:https://support.lenovo.com/us/en/product_security/len-30042

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-8321

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-8321

Trust: 0.8

sources: JVNDB: JVNDB-2020-006844 // CNNVD: CNNVD-202006-806 // NVD: CVE-2020-8321

CREDITS

MengHao,yngwei (@yngweijw),Li of IIE VARAS,driedfish (@d3af1sh)

Trust: 0.6

sources: CNNVD: CNNVD-202006-806

SOURCES

db:JVNDBid:JVNDB-2020-006844
db:CNNVDid:CNNVD-202006-806
db:NVDid:CVE-2020-8321

LAST UPDATE DATE

2024-11-23T21:14:58.517000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-006844date:2020-07-20T00:00:00
db:CNNVDid:CNNVD-202006-806date:2020-06-30T00:00:00
db:NVDid:CVE-2020-8321date:2024-11-21T05:38:42.230

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-006844date:2020-07-20T00:00:00
db:CNNVDid:CNNVD-202006-806date:2020-06-09T00:00:00
db:NVDid:CVE-2020-8321date:2020-06-09T20:15:22.240