CVE-2021-3453: Medium severity Lenovo Thinkpad Helix Firmware vulnerability
Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-3453?
CVE-2021-3453 is a vulnerability found in some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems that allows an attacker with physical access to write to the SPI flash storage.
How severe is CVE-2021-3453?
CVE-2021-3453 has a severity rating of 4.6, which is considered medium.
Which Lenovo systems are affected by CVE-2021-3453?
Lenovo ThinkPad Helix, Lenovo ThinkPad T550, Lenovo ThinkPad W550s, Lenovo ThinkPad X1 Carbon 3rd Gen, Lenovo ThinkPad X250, Lenovo ThinkPad Yoga 15, Lenovo 730s-13iml, Lenovo Ideapad 1-11igl05, Lenovo Ideapad 1-14igl05, Lenovo Ideapad S940-14iil, Lenovo Ideapad S940-14iwl, Lenovo Ideapad Slim 1-11ast-05, Lenovo Ideapad Slim 1-14ast-05, Lenovo V130-15igm, Lenovo V330-15ikb, Lenovo V330-15isk, Lenovo Yoga S730-13iml, Lenovo Yoga S940-14iil, Lenovo Yoga S940-14iwl, Lenovo Ideacentre Aio 5-24imb05, and Lenovo Ideacentre Aio 5-74imb05 are affected by CVE-2021-3453.
How can an attacker exploit CVE-2021-3453?
An attacker with physical access to the affected systems can exploit CVE-2021-3453 by writing to the SPI flash storage.
Where can I find more information about CVE-2021-3453?
You can find more information about CVE-2021-3453 on the Lenovo product security website: https://support.lenovo.com/us/en/product_security/LEN-65529