CVE-2020-8341: Low severity lenovo thinkpad t490 (20nx) firmware vulnerability

Published Sep 1, 2020
·
Updated

In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.

Affected Software

20 affected components
Lenovo Thinkpad T490 \(20nx\) Firmware<n2iet90w
Lenovo Thinkpad T490 \(20nx\)
Lenovo Thinkpad T490 \(20qx\) Firmware<n2iet90w
Lenovo Thinkpad T490 \(20qx\)
Lenovo Thinkpad T490 \(20rx\) Firmware<n2ret16w
Lenovo Thinkpad T490 \(20rx\)
Lenovo Thinkpad T490s \(20nx\) Firmware<n2jet89w
Lenovo Thinkpad T490s \(20nx\)
Lenovo Thinkpad T495 Drift Firmware<2020-08-30
Lenovo Thinkpad T495 Drift
Lenovo Thinkpad T590 \(20nx\) Firmware<n2iet90w
Lenovo Thinkpad T590 \(20nx\)
Lenovo Thinkpad X1 Carbon \(20qx\) Firmware<n2het54w
Lenovo Thinkpad X1 Carbon \(20qx\)
Lenovo Thinkpad X1 Yoga \(20qx\) Firmware<n2het54w
Lenovo Thinkpad X1 Yoga \(20qx\)
Lenovo Thinkpad X390 \(20qx\) Firmware<n2jet89w
Lenovo Thinkpad X390 \(20qx\)
Lenovo Thinkpad X390 \(20sx\) Firmware<n2set18w
Lenovo Thinkpad X390 \(20sx\)

Remediation

Information

No action required. Lenovo has updated BIOS for systems in the product impact section to implement this secondary protection, PRx.

Event History

Sep 1, 2020
CVE Published
via MITRE·09:30 PM
Data Sourced
via MITRE·09:30 PM
RemedyDescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID for this Lenovo systems vulnerability?

The vulnerability ID for this Lenovo systems vulnerability is CVE-2020-8341.

2

What is SMM BIOS Write Protection in Lenovo systems?

In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash.

3

What is the additional layer of protection provided by SPI Protected Range Registers (PRx)?

SPI Protected Range Registers (PRx) provide an additional layer of protection in Lenovo systems.

4

What is the severity of CVE-2020-8341?

The severity of CVE-2020-8341 is low, with a severity value of 2.4.

5

Where can I find more information about this vulnerability?

More information about this vulnerability can be found on the Lenovo product security website.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203