CVE-2020-8341
Summary
| CVE | CVE-2020-8341 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-01 22:15:00 UTC |
| Updated | 2020-09-11 16:21:00 UTC |
| Description | In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | Thinkpad T490s 20nx | - | All | All | All |
| Hardware | Lenovo | Thinkpad T490s 20nx | - | All | All | All |
| Operating System | Lenovo | Thinkpad T490s 20nx Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad T490s 20nx Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad T490 20nx | - | All | All | All |
| Hardware | Lenovo | Thinkpad T490 20nx | - | All | All | All |
| Operating System | Lenovo | Thinkpad T490 20nx Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad T490 20nx Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad T490 20qx | - | All | All | All |
| Hardware | Lenovo | Thinkpad T490 20qx | - | All | All | All |
| Operating System | Lenovo | Thinkpad T490 20qx Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad T490 20qx Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad T490 20rx | - | All | All | All |
| Hardware | Lenovo | Thinkpad T490 20rx | - | All | All | All |
| Operating System | Lenovo | Thinkpad T490 20rx Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad T490 20rx Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad T495 Drift | - | All | All | All |
| Hardware | Lenovo | Thinkpad T495 Drift | - | All | All | All |
| Operating System | Lenovo | Thinkpad T495 Drift Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad T495 Drift Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad T590 20nx | - | All | All | All |
| Hardware | Lenovo | Thinkpad T590 20nx | - | All | All | All |
| Operating System | Lenovo | Thinkpad T590 20nx Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad T590 20nx Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad X1 Carbon 20qx | - | All | All | All |
| Hardware | Lenovo | Thinkpad X1 Carbon 20qx | - | All | All | All |
| Operating System | Lenovo | Thinkpad X1 Carbon 20qx Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad X1 Carbon 20qx Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad X1 Yoga 20qx | - | All | All | All |
| Hardware | Lenovo | Thinkpad X1 Yoga 20qx | - | All | All | All |
| Operating System | Lenovo | Thinkpad X1 Yoga 20qx Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad X1 Yoga 20qx Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad X390 20qx | - | All | All | All |
| Hardware | Lenovo | Thinkpad X390 20qx | - | All | All | All |
| Operating System | Lenovo | Thinkpad X390 20qx Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad X390 20qx Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkpad X390 20sx | - | All | All | All |
| Hardware | Lenovo | Thinkpad X390 20sx | - | All | All | All |
| Operating System | Lenovo | Thinkpad X390 20sx Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkpad X390 20sx Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multi-vendor BIOS Security Vulnerabilities (June 2020) - US | MISC | support.lenovo.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.