- Added submission from Lenovo for LEN-20527 from 2018-09-20.

This commit is contained in:
CVE Team 2018-09-20 16:31:47 -04:00
parent ee6b3c2ea9
commit a290550e69
No known key found for this signature in database
GPG Key ID: 0DA1F9F56BC892E8

View File

@ -1,8 +1,32 @@
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ASSIGNER" : "psirt@lenovo.com",
"ID" : "CVE-2018-9062",
"STATE" : "REJECT"
"STATE" : "PUBLIC",
"TITLE" : "BIOS Modules Unprotected by Intel Boot Guard Vulnerable to Physical Attack"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "some Lenovo ThinkPads",
"version" : {
"version_data" : [
{
"version_value" : "various"
}
]
}
}
]
},
"vendor_name" : "Lenovo Group Ltd."
}
]
}
},
"data_format" : "MITRE",
"data_type" : "CVE",
@ -11,8 +35,32 @@
"description_data" : [
{
"lang" : "eng",
"value" : "** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none."
"value" : "In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "Elevation of privilege"
}
]
}
]
},
"references" : {
"reference_data" : [
{
"refsource" : "CONFIRM",
"url" : "https://support.lenovo.com/us/en/solutions/LEN-20527"
}
]
},
"source" : {
"advisory" : "https://support.lenovo.com/us/en/solutions/LEN-20527",
"discovery" : "EXTERNAL"
}
}