CVE-2021-3719
CVE-2021-3719
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.7EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 Nov 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Lenovo · ThinkCentre and ThinkStation BIOSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →