First published: Tue Jun 09 2020(Updated: )
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Thinkpad T495s Firmware | ||
Lenovo ThinkPad T495s | ||
Lenovo Thinkpad X395 Firmware | ||
Lenovo Thinkpad X395 | ||
Lenovo Thinkpad T495 Firmware | ||
Lenovo ThinkPad T495 | ||
Lenovo Thinkpad A485 Firmware | ||
Lenovo Thinkpad A485 | ||
Lenovo Thinkpad A285 Firmware | ||
Lenovo ThinkPad A285 | ||
Lenovo Thinkpad A475 Firmware | ||
Lenovo Thinkpad A475 | ||
Lenovo Thinkpad A275 Firmware | ||
Lenovo Thinkpad A275 |
Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-30042.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability severity of CVE-2020-8334 is medium with a severity value of 6.8.
The BIOS tamper detection mechanism in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 is designed to trigger and detect unauthorized access attempts, but in this vulnerability, it fails to do so.
The Lenovo ThinkPad models affected by CVE-2020-8334 are T495s, X395, T495, A485, A285, A475, A275.
To prevent unauthorized access, Lenovo recommends applying the firmware updates provided in their security advisory.
You can find more information about CVE-2020-8334 in the Lenovo product security advisory available at the referenced URL.