CVE-2021-3718

MEDIUM

Lenovo ThinkPad Firmware - Denial of Service via Enhanced Biometrics Setting

Title source: llm
STIX 2.1

Description

A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 10.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-232
Status published
Products (42)
lenovo/thinkpad_11e_3rd_gen_firmware < 1.22
lenovo/thinkpad_11e_3rd_gen_firmware < 1.29
lenovo/thinkpad_11e_4th_gen_celeron_firmware < 1.27
lenovo/thinkpad_11e_4th_gen_i3_firmware < 1.22
lenovo/thinkpad_11e_4th_gen_i5_firmware < 1.22
lenovo/thinkpad_11e_4th_gen_i7_firmware < 1.22
lenovo/thinkpad_11e_5th_gen_firmware < 1.13
lenovo/thinkpad_11e_yoga_gen_6_firmware < 1.12
lenovo/thinkpad_13_gen_2_firmware < 1.29
lenovo/thinkpad_e490_firmware < 1.30
... and 32 more
Published Nov 12, 2021
Tracked Since Feb 18, 2026