CVE-2020-8336: Medium severity lenovo thinkpad e14 firmware vulnerability

Published Jun 9, 2020
·
Updated

Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.

Affected Software

76 affected components
Lenovo Thinkpad E14 Firmware<2020-07-10
Lenovo Thinkpad E14
Lenovo Thinkpad E15 Firmware<2020-07-10
Lenovo Thinkpad E15
Lenovo Thinkpad R14 Firmware<2020-07-10
Lenovo Thinkpad R14
Lenovo Thinkpad S3 Gen 2 Firmware<2020-07-10
Lenovo Thinkpad S3 Gen 2
Lenovo Thinkpad E490s Firmware<2020-07-10
Lenovo Thinkpad E490s
Lenovo Thinkpad S3 Firmware<2020-07-10
Lenovo Thinkpad S3
Lenovo Thinkpad E490 Firmware<2020-07-10
Lenovo Thinkpad E490
Lenovo Thinkpad E590 Firmware<2020-07-10
Lenovo Thinkpad E590
Lenovo Thinkpad R490 Firmware<2020-07-10
Lenovo Thinkpad R490
Lenovo Thinkpad R590 Firmware<2020-07-10
Lenovo Thinkpad R590
Lenovo Thinkpad L13 1st Gen Firmware<2020-07-10
Lenovo Thinkpad L13 1st Gen
Lenovo Thinkpad L1415 Gen 1 Firmware<2020-07-10
Lenovo Thinkpad L1415 Gen 1
Lenovo Thinkpad L390 Yoga Firmware<2020-07-10
Lenovo Thinkpad L390 Yoga
Lenovo Thinkpad S2 Yoga 4th Gen Firmware<2020-07-10
Lenovo Thinkpad S2 Yoga 4th Gen
Lenovo Thinkpad L490 Firmware<2020-07-10
Lenovo Thinkpad L490
Lenovo Thinkpad L590 Firmware<2020-07-10
Lenovo Thinkpad L590
Lenovo Thinkpad P1 \(20mx\) Firmware<n2eet47w
Lenovo Thinkpad P1 \(20mx\)
Lenovo Thinkpad P1 \(20qx\) Firmware<n2oet44w
Lenovo Thinkpad P1 \(20qx\)
Lenovo Thinkpad P43s \(20rx\) Firmware<n2iet88w
Lenovo Thinkpad P43s \(20rx\)
Lenovo Thinkpad P52 \(20mx\) Firmware<n2cet51w-1.34
Lenovo Thinkpad P52 \(20mx\)
Lenovo Thinkpad P53 \(20qx\) Firmware<n2net37w
Lenovo Thinkpad P53 \(20qx\)
Lenovo Thinkpad P53s \(20nx\) Firmware<n2iet88w
Lenovo Thinkpad P53s \(20nx\)
Lenovo Thinkpad P72 \(20mx\) Firmware<n2cet51w
Lenovo Thinkpad P72 \(20mx\)
Lenovo Thinkpad P73 \(20qx\) Firmware<n2net37w
Lenovo Thinkpad P73 \(20qx\)
Lenovo Thinkpad T490 \(20nx\) Firmware<n2iet88w
Lenovo Thinkpad T490 \(20nx\)
Lenovo Thinkpad T490 \(20qx\) Firmware<n2iet88w
Lenovo Thinkpad T490 \(20qx\)
Lenovo Thinkpad T490 \(20rx\) Firmware<n2iet88w
Lenovo Thinkpad T490 \(20rx\)
Lenovo Thinkpad T490s \(20nx\) Firmware<n2jet87w
Lenovo Thinkpad T490s \(20nx\)
Lenovo Thinkpad T590 \(20nx\) Firmware<n2iet88w
Lenovo Thinkpad T590 \(20nx\)
Lenovo Thinkpad X1 Carbon \(20qx\) Firmware<n2het47w
Lenovo Thinkpad X1 Carbon \(20qx\)
Lenovo Thinkpad X1 Carbon \(20rx\) Firmware<n2het47w
Lenovo Thinkpad X1 Carbon \(20rx\)
Lenovo Thinkpad X1 Extreme \(20mx\) Firmware<n2eet47w
Lenovo Thinkpad X1 Extreme \(20mx\)
Lenovo Thinkpad X1 Extreme \(20qx\) Firmware<n2oet44w
Lenovo Thinkpad X1 Extreme \(20qx\)
Lenovo Thinkpad X1 Yoga \(20qx\) Firmware<n2het47w
Lenovo Thinkpad X1 Yoga \(20qx\)
Lenovo Thinkpad X1 Yoga \(20sx\) Firmware<n2het47w
Lenovo Thinkpad X1 Yoga \(20sx\)
Lenovo Thinkpad X390 \(20qx\) Firmware<n2jet87w
Lenovo Thinkpad X390 \(20qx\)
Lenovo Thinkpad X390 \(20sx\) Firmware<n2set18w
Lenovo Thinkpad X390 \(20sx\)
Lenovo Thinkpad X390 Yoga Firmware<n2let74w
Lenovo Thinkpad X390 Yoga

Remediation

Information

Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-30042.

Event History

Jun 9, 2020
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
RemedyDescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-8336?

CVE-2020-8336 has been assessed as a moderate severity vulnerability.

2

How do I fix CVE-2020-8336?

To fix CVE-2020-8336, users should update the affected Lenovo ThinkPad firmware to versions released after July 10, 2020.

3

Which Lenovo models are affected by CVE-2020-8336?

CVE-2020-8336 affects multiple Lenovo ThinkPad models with firmware versions prior to July 10, 2020.

4

Can I identify if my device is vulnerable to CVE-2020-8336?

You can determine if your device is vulnerable to CVE-2020-8336 by checking the firmware version against the Lenovo support page.

5

What is the nature of the vulnerability in CVE-2020-8336?

CVE-2020-8336 pertains to inadequate anti-rollback protections for Intel CSME firmware on certain Lenovo ThinkPad models.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203