CVE-2020-8335

T

he BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lenovo:thinkpad_a275_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkpad_a275:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:lenovo:thinkpad_a285_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkpad_a285:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:lenovo:thinkpad_a475_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkpad_a475:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:lenovo:thinkpad_a485_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkpad_a485:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:lenovo:thinkpad_t495_drift_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkpad_t495_drift:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:lenovo:thinkpad_t495s_jazz_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkpad_t495s_jazz:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:lenovo:thinkpad_x1_carbon_\(20bx\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkpad_x1_carbon_\(20bx\):-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:lenovo:thinkpad_x395_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkpad_x395:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:38

Type Values Removed Values Added
CVSS v2 : 4.6
v3 : 6.8
v2 : 4.6
v3 : 6.1
References () https://support.lenovo.com/us/en/product_security/LEN-30042 - Vendor Advisory () https://support.lenovo.com/us/en/product_security/LEN-30042 - Vendor Advisory