First published: Fri Apr 22 2022(Updated: )
A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Ideapad 3-14ada05 Firmware | <e8cn33ww | |
Lenovo Ideapad 3-14ada05 Firmware | ||
Lenovo ideapad 3-14ada6 firmware | <hbcn21ww | |
Lenovo ideapad 3-14ada6 firmware | ||
Lenovo Ideapad 3-14ALC6 | <glcn43ww | |
Lenovo Ideapad 3-14alc6 firmware | ||
Lenovo IdeaPad 3-14ARE05 Firmware | <dzcn42ww | |
Lenovo IdeaPad 3-14ARE05 Firmware | ||
Lenovo Ideapad 3 | <hbcn21ww | |
Lenovo Ideapad 3 | ||
Lenovo Ideapad 3-15ALC6 Firmware | <glcn43ww | |
Lenovo Ideapad 3-15ALC6 Firmware | ||
Lenovo Ideapad 3-15ARE05 Firmware | <dzcn42ww | |
Lenovo Ideapad 3-15are05 firmware | ||
Lenovo Ideapad 3-15IGL05 Firmware | <dvcn23ww | |
Lenovo ideapad 3-15igl05 firmware | ||
Lenovo Ideapad 3-17ADA05 Firmware | <e8cn33ww | |
Lenovo Ideapad 3-17ADA05 Firmware | ||
Lenovo Ideapad 3-17ADA6 | <hbcn21ww | |
Lenovo Ideapad 3 | ||
Lenovo Ideapad 3-17ALC6 Firmware | <glcn43ww | |
Lenovo Ideapad 3-17ALC6 Firmware | ||
Lenovo Ideapad 3-17are05 | <dzcn42ww | |
Lenovo Ideapad 3 | ||
Lenovo Ideapad 3-17iil05 | <emcn52ww | |
Lenovo Ideapad 3-17IIL05 Firmware | ||
Lenovo Ideapad 3-15ada05 | <e8cn33ww | |
Lenovo Ideapad 3 | ||
Lenovo L3-15ITL6 Firmware | <gfcn23ww | |
Lenovo Ideapad 3-15ITL6 | ||
Lenovo L340-15IRH | <bgcn35ww | |
Lenovo L340-15IRH Firmware | ||
Lenovo L340-15IWl Touch Firmware | <atcn46ww | |
Lenovo L340-15IWL Touch | ||
Lenovo L340-15IWL Touch Firmware | <atcn46ww | |
Lenovo L340-15IWL | ||
Lenovo L340-17IRH Firmware | <bgcn35ww | |
Lenovo L340-17IRH Firmware | ||
Lenovo L340-17IWL | <atcn46ww | |
Lenovo L340-17IWL Firmware | ||
Lenovo Legion 5 Pro 16ACH6 Firmware | <hhcn25ww | |
Lenovo Legion 5 Pro 16ACH6H | ||
Lenovo Legion 5 Pro 16ACH6H | <gkcn51ww | |
Lenovo Legion 5 Pro 16ACH6H | ||
Lenovo Legion 5 Pro 16ITH6H Firmware | <h1cn46ww | |
Lenovo Legion 5 Pro 16ITH6 | ||
Lenovo Legion 5 Pro 16ITH6H Firmware | <h1cn46ww | |
Lenovo Legion 5 Pro 16ITH6 | ||
Lenovo Legion 5-15ACH6A Firmware | <hhcn25ww | |
Lenovo Legion 5-15ACH6 Firmware | ||
Lenovo Legion 5-15ACH6 Firmware | <g9cn28ww | |
Lenovo Legion 5-15ACH6A Firmware | ||
Lenovo Legion 5 - 17ACH6H | <gkcn51ww | |
Lenovo Legion 5-15ACH6H Firmware | ||
Lenovo Legion 5 15ITH6 Firmware | <h1cn46ww | |
Lenovo Legion 5 15ITH6 Firmware | ||
Lenovo Legion 5 15ITH6H | <h1cn46ww | |
Lenovo Legion 5 15ITH6H | ||
Lenovo Legion 5-17ACH6H Firmware | <hhcn25ww | |
Lenovo Legion 5-17ACH6 Firmware | ||
Lenovo Legion 5-17ACH6H Firmware | <gkcn51ww | |
Lenovo Legion 5 - 17ACH6H | ||
Lenovo Legion 5-17ITH6H Firmware | <h1cn46ww | |
Lenovo Legion 5 | ||
Lenovo Legion 5 Firmware | <h1cn46ww | |
Lenovo Legion 5-17ITH6H Firmware | ||
Lenovo Legion 7 16ACHG6 Firmware | <gkcn51ww | |
Lenovo Legion 7 16ACHG6 Firmware | ||
Lenovo Legion 7-16ITHG6 | <gkcn51ww | |
Lenovo Legion 7 16ITHG6 Firmware | ||
Lenovo Legion Y540 | <bhcn44ww | |
Lenovo Legion Y540-15IRH Firmware | ||
Lenovo Legion Y540-15IRH Firmware | <bhcn44ww | |
Lenovo Legion Y540-15IRH | ||
Lenovo Legion Y540-17IRH | <bhcn44ww | |
Lenovo Legion Y540 | ||
Lenovo Legion Y540-17IRH Firmware | <bhcn44ww | |
Lenovo Legion Y540-17IRH-PG0 Firmware | ||
Lenovo Legion Y545 Firmware | <bhcn44ww | |
Lenovo Legion Y545 PG0 | ||
Lenovo Legion Y545 Firmware | <bhcn44ww | |
Lenovo Legion Y545 | ||
Lenovo Legion Y7000P 2019 Firmware | <bhcn44ww | |
Lenovo Legion Y7000 2019 | ||
Lenovo Legion Y7000-2019 Firmware | <bhcn44ww | |
Lenovo Legion Y7000 2019 | ||
Lenovo S145-14IGM Firmware | <bucn31ww | |
Lenovo S145-14API | ||
Lenovo S145-14IGM Firmware | <aycn26ww | |
Lenovo S145-14AST | ||
Lenovo S145-14IGM Firmware | <awcn28ww | |
Lenovo S145-14API | ||
Lenovo S145-14IGM Firmware | <dkcn54ww | |
Lenovo S145-14IIL Firmware | ||
Lenovo S145-15api Firmware | <bucn31ww | |
Lenovo S145-15api Firmware | ||
Lenovo S145-15AST Firmware | <aycn26ww | |
Lenovo S145-15api Firmware | ||
Lenovo S145-15IGM | <awcn28ww | |
Lenovo S145 | ||
Lenovo s145-15iil | <dkcn54ww | |
Lenovo s145-15iil firmware | ||
Lenovo S540-13API | <cxcn34ww | |
Lenovo S540-13API Firmware | ||
Lenovo V14 G2 ACL Firmware | <glcn43ww | |
Lenovo V14 G2 ACL | ||
Lenovo v14-ada firmware | <e8cn33ww | |
Lenovo v14-ada firmware | ||
Lenovo v14-are firmware | <dzcn42ww | |
Lenovo v14-are firmware | ||
Lenovo v14-igl firmware | <dvcn23ww | |
Lenovo v14-igl firmware | ||
Lenovo v14-iil firmware | <dkcn54ww | |
Lenovo v14-iil firmware | ||
Lenovo v140-15iwl | <atcn46ww | |
Lenovo v140-15iwl firmware | ||
Lenovo V15 G2-ALC | <glcn43ww | |
Lenovo v15 g2 ijl | ||
Lenovo v15-ada firmware | <e8cn33ww | |
Lenovo v15-ada firmware | ||
Lenovo v15-igl firmware | <dvcn23ww | |
Lenovo v15-igl | ||
Lenovo v15-iil | <dkcn54ww | |
Lenovo v15-iil firmware | ||
Lenovo v17-iil firmware | <emcn52ww | |
Lenovo v17-iil | ||
Lenovo v340-17iwl | <atcn46ww | |
Lenovo v340-17iwl firmware | ||
Lenovo Yoga Slim 7 Pro 14ACH5 Firmware | <hecn24ww | |
Lenovo Yoga Slim 7 Pro-14ach5 | ||
Lenovo Yoga Slim 7 Pro 14ACH5 O Firmware | <hecn24ww | |
Lenovo Yoga Slim 7 Pro-14ach5 | ||
Lenovo Ideapad 3 14iil05 Firmware | <dvcn23ww | |
Lenovo Ideapad 3 14iil05 Firmware | ||
Lenovo Ideapad 3-14IGL05 Firmware | <emcn52ww | |
Lenovo ideapad 3-14igl05 firmware | ||
Lenovo Ideapad 3-15IIL05 Firmware | <emcn52ww | |
Lenovo Ideapad 3 15iil05 | ||
Lenovo ideapad 5-14are05 firmware | <e7cn44ww | |
Lenovo Ideapad 5-15are05 Firmware | ||
Lenovo Ideapad Creator 5-15imh05 Firmware | <egcn36ww | |
Lenovo Ideapad Creator 5-15imh05 Firmware | ||
Lenovo Ideapad Gaming 3-15ARH05 | <fccn17ww | |
Lenovo Ideapad Gaming 3-15ARH05 Firmware | ||
Lenovo Ideapad Gaming 3-15IMH05 | <egcn36ww | |
Lenovo Ideapad Gaming 3-15IMH05 Firmware |
Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-73440.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-3971 is rated as medium risk due to potential unauthorized modifications to firmware protection regions.
CVE-2021-3971 affects multiple Lenovo IdeaPad notebook models, specifically those with certain firmware versions.
To fix CVE-2021-3971, users should update their firmware to the latest version provided by Lenovo that addresses this vulnerability.
CVE-2021-3971 requires elevated privileges, meaning an attacker would need physical access to the device to exploit this vulnerability.
Exploitation of CVE-2021-3971 could compromise the integrity of firmware, potentially allowing malicious modifications to the system.