First published: Fri Nov 12 2021(Updated: )
A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
lenovo ThinkPad yoga 11e 3rd gen firmware | <=1.22 | |
Lenovo ThinkPad Yoga 11e 3rd Gen | ||
lenovo ThinkPad yoga 11e 3rd gen firmware | <=1.29 | |
Lenovo ThinkPad 11e 4th Gen Firmware | <=1.22 | |
Lenovo ThinkPad 11e 4th Gen i3 | ||
Lenovo ThinkPad 11e 4th Gen Firmware | <=1.22 | |
Lenovo ThinkPad 11e 4th Gen with Intel i7 | ||
Lenovo ThinkPad 11e 4th Gen Firmware | <=1.22 | |
Lenovo ThinkPad 11e | ||
Lenovo ThinkPad 11e 4th Gen Firmware | <=1.27 | |
Lenovo ThinkPad 11e 4th Gen Celeron Firmware | ||
Lenovo ThinkPad 11e Yoga Gen 6 Firmware | <=1.12 | |
Lenovo ThinkPad 11e Yoga Gen 6 Firmware | ||
Lenovo ThinkPad 13 2nd Gen Firmware | <=1.29 | |
Lenovo ThinkPad 13 2nd Gen Firmware | ||
Lenovo ThinkPad L13 | <=1.31 | |
Lenovo ThinkPad L13 | ||
Lenovo ThinkPad L13 Gen 2 | <=1.11 | |
Lenovo ThinkPad L13 Gen 2 Firmware | ||
Lenovo ThinkPad L13 Gen 2 | <=1.08 | |
Lenovo ThinkPad L13 Yoga Gen 4 Firmware | <=1.31 | |
Lenovo ThinkPad L13 Yoga Gen 1 | ||
Lenovo ThinkPad L13 Yoga Gen 2 | <=1.11 | |
Lenovo 13w Yoga Gen 2 Firmware | ||
Lenovo ThinkPad L13 Yoga Gen 2 | <=1.08 | |
Lenovo ThinkPad L14 Gen 1 | <1.15 | |
Lenovo ThinkPad L14 | ||
Lenovo Thinkpad L14 Firmware | <1.20.1.17 | |
Lenovo ThinkPad L14 | ||
Lenovo ThinkPad L15 Gen 1 Firmware | <1.15 | |
Lenovo ThinkPad L15 Gen 1 Firmware | ||
Lenovo ThinkPad L15 | <1.20.1.17 | |
Lenovo ThinkPad L15 | ||
Lenovo ThinkPad L380 Firmware | <=1.26 | |
Lenovo ThinkPad L380 | ||
Lenovo ThinkPad L380 Yoga Firmware | <=1.26 | |
Lenovo ThinkPad L380 Yoga Firmware | ||
Lenovo ThinkPad L390 Yoga Firmware | <=1.35 | |
Lenovo ThinkPad L390 Yoga Firmware | ||
Lenovo ThinkPad L390 Yoga Firmware | <=1.35 | |
Lenovo Thinkpad L390 Firmware | ||
Lenovo ThinkPad S5 2nd Generation Firmware | <=1.28 | |
Lenovo ThinkPad S5 2nd Gen Firmware | ||
Lenovo ThinkPad T460 firmware | <=1.43.1.11 | |
Lenovo ThinkPad T460 firmware | ||
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | <=2021-09-30 | |
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | ||
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | <=2021-09-30 | |
Lenovo ThinkPad S2 Yoga Gen 6 Firmware | ||
Lenovo ThinkPad X12 Detachable Gen 1 Firmware | <1.16 | |
Lenovo ThinkPad X12 Detachable Gen 1 Firmware | ||
Lenovo ThinkPad x260 firmware | <=1.47\/1.15 | |
Lenovo ThinkPad x260 | ||
Lenovo ThinkPad x380 Yoga Firmware | <=1.34 | |
Lenovo ThinkPad X380 Yoga | ||
Lenovo ThinkPad X390 Yoga Firmware | <n2let87w | |
Lenovo ThinkPad X390 Yoga Firmware | ||
Lenovo ThinkPad 11e (5th Gen) | <=1.13 | |
Lenovo ThinkPad 11e (5th Gen) | ||
Lenovo ThinkPad Yoga 370 Firmware | ||
Lenovo ThinkPad X1 Fold Gen 1 Firmware | <n2pet50w | |
Lenovo ThinkPad X1 Fold Gen 1 Firmware |
Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-72619.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-3843 is classified as high due to its potential for local code execution.
To fix CVE-2021-3843, you should update the firmware of affected Lenovo ThinkPad models to the latest version provided by Lenovo.
The affected models include various Lenovo ThinkPad 11e, 4th Gen i3/i5/i7, 13 Gen 2, L13, L14, S2 Gen 6, T460, and more.
No, CVE-2021-3843 requires local access and elevated privileges for exploitation.
Currently, the recommended mitigation for CVE-2021-3843 is to apply the firmware update as there are no known workarounds available.