← back
CVE-2021-3453

CVE-2021-3453

CVSS 6.8 MEDIUMEPSS 0.2%CWE-693
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.8EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
16 Jul 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Lenovo · BIOS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →