7.2
Advisory Published
Updated

CVE-2019-6171

First published: Mon Aug 19 2019(Updated: )

A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.

Credit: psirt@lenovo.com

Affected SoftwareAffected VersionHow to fix
Lenovo 20f1 Firmware
Lenovo 20f1
Lenovo 20f2 Firmware
Lenovo 20f2
Lenovo 20jq Firmware
Lenovo 20jq
Lenovo 20jr Firmware
Lenovo 20jr
Lenovo 20g9 Firmware
Lenovo 20g9
Lenovo 20gb Firmware
Lenovo 20gb
Lenovo 20g8 Firmware
Lenovo 20g8
Lenovo 20ga Firmware
Lenovo 20ga
Lenovo 20ht Firmware
Lenovo 20ht
Lenovo 20hv Firmware
Lenovo 20hv
Lenovo 20hs Firmware
Lenovo 20hs
Lenovo 20hu Firmware
Lenovo 20hu
Lenovo 20lr Firmware
Lenovo 20lr
Lenovo 20lq Firmware
Lenovo 20lq
Lenovo 20ln Firmware
Lenovo 20ln
Lenovo 20lm Firmware
Lenovo 20lm
Lenovo 20j1 Firmware
Lenovo 20j1
Lenovo 20j2 Firmware
Lenovo 20j2
Lenovo 20kc Firmware
Lenovo 20kc
Lenovo 20kd Firmware
Lenovo 20kd
Lenovo 20mw Firmware
Lenovo 20mw
Lenovo 20mx Firmware
Lenovo 20mx
Lenovo 20kl Firmware
Lenovo 20kl
Lenovo 20km Firmware
Lenovo 20km
Lenovo 20mu Firmware
Lenovo 20mu
Lenovo 20mv Firmware
Lenovo 20mv
Lenovo 20dc Firmware
Lenovo 20dc
Lenovo 20dd Firmware
Lenovo 20dd
Lenovo 30eh Firmware
Lenovo 30eh
Lenovo 20df Firmware
Lenovo 20df
Lenovo 20dg Firmware
Lenovo 20dg
Lenovo 20e0 Firmware
Lenovo 20e0
Lenovo 20de Firmware
Lenovo 20de
Lenovo 20dh Firmware
Lenovo 20dh
Lenovo 20et Firmware
Lenovo 20et
Lenovo 20eu Firmware
Lenovo 20eu
Lenovo 20ex Firmware
Lenovo 20ex
Lenovo 20ey Firmware
Lenovo 20ey
Lenovo 20h1 Firmware
Lenovo 20h1
Lenovo 20h2 Firmware
Lenovo 20h2
Lenovo 20h5 Firmware
Lenovo 20h5
Lenovo 20h6 Firmware
Lenovo 20h6
Lenovo 20h4 Firmware
Lenovo 20h4
Lenovo 20h8 Firmware
Lenovo 20h8
Lenovo 20kn Firmware
Lenovo 20kn
Lenovo 20kq Firmware
Lenovo 20kq
Lenovo 20ks Firmware
Lenovo 20ks
Lenovo 20kt Firmware
Lenovo 20kt
Lenovo 20ku Firmware
Lenovo 20ku
Lenovo 20kv Firmware
Lenovo 20kv
Lenovo 20n8 Firmware
Lenovo 20n8
Lenovo 20n9 Firmware
Lenovo 20n9
Lenovo 20ng Firmware
Lenovo 20ng
Lenovo 3xxx Firmware
Lenovo 3xxx
Lenovo 20nr Firmware
Lenovo 20nr
Lenovo 20ns Firmware
Lenovo 20ns
Lenovo 20nt Firmware
Lenovo 20nt
Lenovo 20nu Firmware
Lenovo 20nu
Lenovo 246x Firmware
Lenovo 246x
Lenovo 247x Firmware
Lenovo 247x
Lenovo 248x Firmware
Lenovo 248x
Lenovo 20ds Firmware
Lenovo 20ds
Lenovo 20dt Firmware
Lenovo 20dt
Lenovo 20fu Firmware
Lenovo 20fu
Lenovo 20j4 Firmware
Lenovo 20j4
Lenovo 20ju Firmware
Lenovo 20ju
Lenovo 20jv Firmware
Lenovo 20jv
Lenovo 20ls Firmware
Lenovo 20ls
Lenovo 20lt Firmware
Lenovo 20lt
Lenovo 20l2 Firmware
Lenovo 20l2
Lenovo 20lx Firmware
Lenovo 20lx
Lenovo 20ja Firmware
Lenovo 20ja
Lenovo 20dq Firmware
Lenovo 20dq
Lenovo 20dr Firmware
Lenovo 20dr
Lenovo 20g5 Firmware
Lenovo 20g5
Lenovo 20g4 Firmware
Lenovo 20g4
Lenovo 20b0 Firmware
Lenovo 20b0
Lenovo 20b3 Firmware
Lenovo 20b3
Lenovo 234x Firmware
Lenovo 234x
Lenovo 235x Firmware
Lenovo 235x
Lenovo 20a9 Firmware
Lenovo 20a9
Lenovo 20aa Firmware
Lenovo 20aa
Lenovo 20ab Firmware
Lenovo 20ab
Lenovo 20ac Firmware
Lenovo 20ac
Lenovo 20b6 Firmware
Lenovo 20b6
Lenovo 20b7 Firmware
Lenovo 20b7
Lenovo 20aq Firmware
Lenovo 20aq
Lenovo 20ar Firmware
Lenovo 20ar
Lenovo 20an Firmware
Lenovo 20an
Lenovo 20aw Firmware
Lenovo 20aw
Lenovo 20bu Firmware
Lenovo 20bu
Lenovo 20bv Firmware
Lenovo 20bv
Lenovo 20dj Firmware
Lenovo 20dj
Lenovo 20bw Firmware
Lenovo 20bw
Lenovo 20bx Firmware
Lenovo 20bx
Lenovo 20fm Firmware
Lenovo 20fm
Lenovo 20fn Firmware
Lenovo 20fn
Lenovo 20fw Firmware
Lenovo 20fw
Lenovo 20fx Firmware
Lenovo 20fx
Lenovo 239x Firmware
Lenovo 239x
Lenovo 242x Firmware
Lenovo 242x
Lenovo 243x Firmware
Lenovo 243x
Lenovo 20be Firmware
Lenovo 20be
Lenovo 20bf Firmware
Lenovo 20bf
Lenovo 244x Firmware
Lenovo 244x
Lenovo 20bg Firmware
Lenovo 20bg
Lenovo 20ef Firmware
Lenovo 20ef
Lenovo 20eg Firmware
Lenovo 20eg
Lenovo 34xx Firmware
Lenovo 34xx
Lenovo 20a7 Firmware
Lenovo 20a7
Lenovo 20a8 Firmware
Lenovo 20a8
Lenovo 336x Firmware
Lenovo 336x
Lenovo 337x Firmware
Lenovo 337x
Lenovo 20bl Firmware
Lenovo 20bl
Lenovo 20bm Firmware
Lenovo 20bm
Lenovo 343x Firmware
Lenovo 343x
Lenovo 344x Firmware
Lenovo 344x
Lenovo 230x Firmware
Lenovo 230x
Lenovo 232x Firmware
Lenovo 232x
Lenovo 233x Firmware
Lenovo 233x
Lenovo 20al Firmware
Lenovo 20al
Lenovo 20am Firmware
Lenovo 20am
Lenovo 20aj Firmware
Lenovo 20aj
Lenovo 20ak Firmware
Lenovo 20ak
Lenovo 20hn Firmware
Lenovo 20hn
Lenovo 20hm Firmware
Lenovo 20hm
Lenovo 20k5 Firmware
Lenovo 20k5
Lenovo 20k6 Firmware
Lenovo 20k6
Lenovo 20lh Firmware
Lenovo 20lh
Lenovo 20lj Firmware
Lenovo 20lj
Lenovo 20nn Firmware
Lenovo 20nn
Lenovo 20nq Firmware
Lenovo 20nq
Lenovo 20da Firmware
Lenovo 20da
Lenovo 20jh Firmware
Lenovo 20jh
Lenovo 20jj Firmware
Lenovo 20jj

Remedy

Update to the version of BIOS (or later) described for your system in the Product Impact section of LEN-27764.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203