CVE-2020-8335
CVE-2020-8335
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.1EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
01 Sep 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Affected products
Lenovo · ThinkPad A285 BIOSLenovo · ThinkPad A485 BIOSLenovo · ThinkPad T495 BIOSLenovo · ThinkPad T495s/X395 BIOSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →