CVE-2019-6171: High severity lenovo 20f1 vulnerability
A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6171?
CVE-2019-6171 is classified as moderate severity, allowing a user with administrative access to potentially update firmware with unsigned code.
How do I fix CVE-2019-6171?
To mitigate CVE-2019-6171, users should apply the latest firmware updates provided by Lenovo for their affected ThinkPad systems.
Which systems are affected by CVE-2019-6171?
CVE-2019-6171 affects various BIOS versions of older Lenovo ThinkPad models.
Can CVE-2019-6171 be exploited remotely?
CVE-2019-6171 requires physical access or administrative privileges, making remote exploitation unlikely.
What should I do if I suspect exploitation of CVE-2019-6171?
If you suspect exploitation of CVE-2019-6171, immediately secure your system and assess administrative access logs for unauthorized changes.