Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-8335


The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access.


Published

2020-09-01T22:15:10.313

Last Modified

2024-11-21T05:38:43.957

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System lenovo thinkpad_a275_firmware < 2020-08-30 Yes
Hardware lenovo thinkpad_a275 - No
Operating System lenovo thinkpad_a285_firmware < 2020-08-30 Yes
Hardware lenovo thinkpad_a285 - No
Operating System lenovo thinkpad_a475_firmware < 2020-08-30 Yes
Hardware lenovo thinkpad_a475 - No
Operating System lenovo thinkpad_a485_firmware < 2020-08-30 Yes
Hardware lenovo thinkpad_a485 - No
Operating System lenovo thinkpad_t495_drift_firmware < 2020-08-30 Yes
Hardware lenovo thinkpad_t495_drift - No
Operating System lenovo thinkpad_t495s_jazz_firmware < 2020-08-30 Yes
Hardware lenovo thinkpad_t495s_jazz - No
Operating System lenovo thinkpad_x1_carbon_\(20bx\)_firmware < n14et54w Yes
Hardware lenovo thinkpad_x1_carbon_\(20bx\) - No
Operating System lenovo thinkpad_x395_firmware < 2020-08-30 Yes
Hardware lenovo thinkpad_x395 - No

References