2.4
Advisory Published
Updated

CVE-2020-8341

First published: Tue Sep 01 2020(Updated: )

In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.

Credit: psirt@lenovo.com

Affected SoftwareAffected VersionHow to fix
Lenovo Thinkpad T490 \(20nx\) Firmware<n2iet90w
Lenovo Thinkpad T490 \(20nx\)
Lenovo Thinkpad T490 \(20qx\) Firmware<n2iet90w
Lenovo Thinkpad T490 \(20qx\)
Lenovo Thinkpad T490 \(20rx\) Firmware<n2ret16w
Lenovo Thinkpad T490 \(20rx\)
Lenovo Thinkpad T490s \(20nx\) Firmware<n2jet89w
Lenovo Thinkpad T490s \(20nx\)
Lenovo Thinkpad T495 Drift Firmware<2020-08-30
Lenovo Thinkpad T495 Drift
Lenovo Thinkpad T590 \(20nx\) Firmware<n2iet90w
Lenovo Thinkpad T590 \(20nx\)
Lenovo Thinkpad X1 Carbon \(20qx\) Firmware<n2het54w
Lenovo Thinkpad X1 Carbon \(20qx\)
Lenovo Thinkpad X1 Yoga \(20qx\) Firmware<n2het54w
Lenovo Thinkpad X1 Yoga \(20qx\)
Lenovo Thinkpad X390 \(20qx\) Firmware<n2jet89w
Lenovo Thinkpad X390 \(20qx\)
Lenovo Thinkpad X390 \(20sx\) Firmware<n2set18w
Lenovo Thinkpad X390 \(20sx\)

Remedy

No action required. Lenovo has updated BIOS for systems in the product impact section to implement this secondary protection, PRx.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the vulnerability ID for this Lenovo systems vulnerability?

    The vulnerability ID for this Lenovo systems vulnerability is CVE-2020-8341.

  • What is SMM BIOS Write Protection in Lenovo systems?

    In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash.

  • What is the additional layer of protection provided by SPI Protected Range Registers (PRx)?

    SPI Protected Range Registers (PRx) provide an additional layer of protection in Lenovo systems.

  • What is the severity of CVE-2020-8341?

    The severity of CVE-2020-8341 is low, with a severity value of 2.4.

  • Where can I find more information about this vulnerability?

    More information about this vulnerability can be found on the Lenovo product security website.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203