Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-5247


The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer RQ940, RS140, TS140, TS240, TS440, and TS540 devices; and ThinkStation E32, P300, and P310 devices might allow local users or physically proximate attackers to bypass the Secure Boot protection mechanism by leveraging an AMI test key.


Published

2016-09-22T15:59:00.147

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-254

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System lenovo bios - Yes
Hardware lenovo thinkcentre_e93 - No
Hardware lenovo thinkcentre_m6500t\/s - No
Hardware lenovo thinkcentre_m6600 - No
Hardware lenovo thinkcentre_m6600q - No
Hardware lenovo thinkcentre_m6600t\/s - No
Hardware lenovo thinkcentre_m73p - No
Hardware lenovo thinkcentre_m800 - No
Hardware lenovo thinkcentre_m83 - No
Hardware lenovo thinkcentre_m8500t\/s - No
Hardware lenovo thinkcentre_m8600t\/s - No
Hardware lenovo thinkcentre_m900 - No
Hardware lenovo thinkcentre_m93 - No
Hardware lenovo thinkcentre_m93p - No
Hardware lenovo thinkserver_rq940 - No
Hardware lenovo thinkserver_rs140 - No
Hardware lenovo thinkserver_ts140 - No
Hardware lenovo thinkserver_ts240 - No
Hardware lenovo thinkserver_ts440 - No
Hardware lenovo thinkserver_ts540 - No
Hardware lenovo thinkstation_e32 - No
Hardware lenovo thinkstation_p300 - No
Hardware lenovo thinkstation_p310 - No

References