CVE-2021-3843

MEDIUM

Lenovo ThinkPad Firmware - Authenticated Arbitrary Code Execution via SMI EEPROM Access

Title source: llm
STIX 2.1

Description

A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0004
EPSS Percentile 11.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (32)
lenovo/thinkpad_11e_3rd_gen_firmware < 1.22
lenovo/thinkpad_11e_3rd_gen_firmware < 1.29
lenovo/thinkpad_11e_4th_gen_celeron_firmware < 1.27
lenovo/thinkpad_11e_4th_gen_i3_firmware < 1.22
lenovo/thinkpad_11e_4th_gen_i5_firmware < 1.22
lenovo/thinkpad_11e_4th_gen_i7_firmware < 1.22
lenovo/thinkpad_11e_5th_gen_firmware < 1.13
lenovo/thinkpad_11e_yoga_gen_6_firmware < 1.12
lenovo/thinkpad_13_gen_2_firmware < 1.29
lenovo/thinkpad_l13_firmware < 1.31
... and 22 more
Published Nov 12, 2021
Tracked Since Feb 18, 2026