A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.

Project Subscriptions

Vendors Products
20a7 Firmware Subscribe
20a8 Firmware Subscribe
20a9 Firmware Subscribe
20aa Firmware Subscribe
20ab Firmware Subscribe
20ac Firmware Subscribe
20aj Firmware Subscribe
20ak Firmware Subscribe
20al Firmware Subscribe
20am Firmware Subscribe
20an Firmware Subscribe
20aq Firmware Subscribe
20ar Firmware Subscribe
20aw Firmware Subscribe
20b0 Firmware Subscribe
20b3 Firmware Subscribe
20b6 Firmware Subscribe
20b7 Firmware Subscribe
20be Firmware Subscribe
20bf Firmware Subscribe
20bg Firmware Subscribe
20bl Firmware Subscribe
20bm Firmware Subscribe
20bu Firmware Subscribe
20bv Firmware Subscribe
20bw Firmware Subscribe
20bx Firmware Subscribe
20d9 Firmware Subscribe
20da Firmware Subscribe
20dc Firmware Subscribe
20dd Firmware Subscribe
20de Firmware Subscribe
20df Firmware Subscribe
20dg Firmware Subscribe
20dh Firmware Subscribe
20dj Firmware Subscribe
20dq Firmware Subscribe
20dr Firmware Subscribe
20ds Firmware Subscribe
20dt Firmware Subscribe
20e0 Firmware Subscribe
20ef Firmware Subscribe
20eg Firmware Subscribe
20et Firmware Subscribe
20eu Firmware Subscribe
20ev Firmware Subscribe
20ew Firmware Subscribe
20ex Firmware Subscribe
20ey Firmware Subscribe
20f1 Firmware Subscribe
20f2 Firmware Subscribe
20f5 Firmware Subscribe
20f6 Firmware Subscribe
20fm Firmware Subscribe
20fn Firmware Subscribe
20fu Firmware Subscribe
20fv Firmware Subscribe
20fw Firmware Subscribe
20fx Firmware Subscribe
20g4 Firmware Subscribe
20g5 Firmware Subscribe
20g8 Firmware Subscribe
20g9 Firmware Subscribe
20ga Firmware Subscribe
20gb Firmware Subscribe
20h1 Firmware Subscribe
20h2 Firmware Subscribe
20h4 Firmware Subscribe
20h5 Firmware Subscribe
20h6 Firmware Subscribe
20h8 Firmware Subscribe
20hm Firmware Subscribe
20hn Firmware Subscribe
20hs Firmware Subscribe
20ht Firmware Subscribe
20hu Firmware Subscribe
20hv Firmware Subscribe
20j1 Firmware Subscribe
20j2 Firmware Subscribe
20j4 Firmware Subscribe
20j5 Firmware Subscribe
20j6 Firmware Subscribe
20j7 Firmware Subscribe
20ja Firmware Subscribe
20jh Firmware Subscribe
20jj Firmware Subscribe
20jq Firmware Subscribe
20jr Firmware Subscribe
20ju Firmware Subscribe
20jv Firmware Subscribe
20k5 Firmware Subscribe
20k6 Firmware Subscribe
20kc Firmware Subscribe
20kd Firmware Subscribe
20kl Firmware Subscribe
20km Firmware Subscribe
20kn Firmware Subscribe
20kq Firmware Subscribe
20ks Firmware Subscribe
20kt Firmware Subscribe
20ku Firmware Subscribe
20kv Firmware Subscribe
20l2 Firmware Subscribe
20lh Firmware Subscribe
20lj Firmware Subscribe
20lm Firmware Subscribe
20ln Firmware Subscribe
20lq Firmware Subscribe
20lr Firmware Subscribe
20ls Firmware Subscribe
20lt Firmware Subscribe
20lx Firmware Subscribe
20m5 Firmware Subscribe
20m6 Firmware Subscribe
20m7 Firmware Subscribe
20m8 Firmware Subscribe
20mu Firmware Subscribe
20mv Firmware Subscribe
20mw Firmware Subscribe
20mx Firmware Subscribe
20n8 Firmware Subscribe
20n9 Firmware Subscribe
20ng Firmware Subscribe
20nn Firmware Subscribe
20nq Firmware Subscribe
20nr Firmware Subscribe
20ns Firmware Subscribe
20nt Firmware Subscribe
20nu Firmware Subscribe
230x Firmware Subscribe
232x Firmware Subscribe
233x Firmware Subscribe
234x Firmware Subscribe
235x Firmware Subscribe
239x Firmware Subscribe
242x Firmware Subscribe
243x Firmware Subscribe
244x Firmware Subscribe
246x Firmware Subscribe
247x Firmware Subscribe
248x Firmware Subscribe
30eh Firmware Subscribe
336x Firmware Subscribe
337x Firmware Subscribe
343x Firmware Subscribe
344x Firmware Subscribe
34xx Firmware Subscribe
3xxx Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-15738 A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
Fixes

Solution

Update to the version of BIOS (or later) described for your system in the Product Impact section of LEN-27764.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-16T20:03:17.346Z

Reserved: 2019-01-11T00:00:00

Link: CVE-2019-6171

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-19T15:15:11.653

Modified: 2024-11-21T04:46:05.243

Link: CVE-2019-6171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses