CVE-2020-8341: Low severity lenovo thinkpad t490 (20nx) firmware vulnerability
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Lenovo systems vulnerability?
The vulnerability ID for this Lenovo systems vulnerability is CVE-2020-8341.
What is SMM BIOS Write Protection in Lenovo systems?
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash.
What is the additional layer of protection provided by SPI Protected Range Registers (PRx)?
SPI Protected Range Registers (PRx) provide an additional layer of protection in Lenovo systems.
What is the severity of CVE-2020-8341?
The severity of CVE-2020-8341 is low, with a severity value of 2.4.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found on the Lenovo product security website.