{ "id": "CVE-2016-8224", "sourceIdentifier": "psirt@lenovo.com", "published": "2016-11-29T20:59:02.437", "lastModified": "2016-12-06T19:15:27.513", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system." }, { "lang": "es", "value": "Una vulnerabilidad ha sido identificada en algunos sistemas Lenovo Notebook y ThinkServer donde un atacante con privilegios administrativos en un sistema podr\u00eda instalar un programa que evita protecciones Intel Management Engine (ME). Esto podr\u00eda resultar en una denegaci\u00f3n de servicio o ataque de escalamiento de privilegios en el sistema." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseScore": 4.4, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 0.8, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:S/C:N/I:N/A:C", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 4.6 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 3.1, "impactScore": 6.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-310" } ] } ], "configurations": [ { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "61D66F0D-6C60-4CF6-A509-C6FAC2E22F95" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_110_14ibr_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "F95D809E-23E0-4887-826D-F3078B3C9ACF" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_110_15ibr_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "647044E0-5561-4C2C-9CA7-6C3CFBC5601B" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_b70_80_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "50FCCB25-38AE-4D4E-9A2C-8F1F071ED246" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_e31_80_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "2C30497A-245A-42E5-AC9F-C853EFE0E13C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_e40_80_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "F6119EA0-4B8A-4E66-99E3-22FFB75C1F6D" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_e41_80_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "31EC5648-5CD3-47A5-8258-4384B2CD8B3A" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_e51_80_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "676B6906-60E9-41A1-A85A-D08EFE5DCE8A" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_g40_80_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "1648A659-67C5-4387-B74B-7194FF212C47" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_g50_80_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "CB179FE4-7FD2-45E0-8141-923ED46E1AC3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_g50_80_touch_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "61E6087F-0E54-4411-838A-1AF443D0684F" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_ideapad_300_14ibr_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "7FAC9552-F856-4C7A-BD0D-8391D31DC74C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_ideapad_300_14isk_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "546DAD7B-58D6-4E33-8639-4B54C88421EC" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_ideapad_300_15ibr_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "BEC25079-36F5-4312-8F9D-AE895C86DF64" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_ideapad_300_15isk_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "4C1B0078-6F39-4093-914F-C5154292AC5F" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_ideapad_300_17isk_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "5927B8CC-9D5E-4AED-B40A-604B50596C4B" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_ideapad_510s_12isk_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "B03AAC7F-CF2E-46BF-90F7-B9ED040AEF56" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_k21_80_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "79E603B0-C0C1-44CC-ADB2-F8F5805CE455" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_k41_80_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "0B1F5A20-2E32-4211-8946-5F8E4713726D" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_miix_710_12ikb_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "DED6589D-4A77-4A8F-8762-183739D8DA25" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_xiaoxin_air_12_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "DD7EB8FF-205C-47D7-BCE4-72576CCF0202" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_yoga_510_14isk_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "46265B64-69F5-470C-A7D1-72620B42CF4C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_yoga_510_15isk_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "39FC8894-2619-4BB5-8B1E-CBA7134045EE" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_yoga_710_11ikb_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "77E0BD48-00CA-4FA7-A622-750727BC8D24" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_yoga_710_11isk_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "01C6DF33-6F13-4A40-AFBA-98D36CB7BE70" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_yoga_900_13isk_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "6118B0D3-F6EB-42B9-8C82-85ECF5B41B94" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:notebook_yoga_900s_12isk_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "B0FBA5BE-CAA5-490D-9711-EE0B8E3D0305" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:thinkserver_ts150_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "26622047-8020-4512-BC20-9C4B26C41E20" }, { "vulnerable": true, "criteria": "cpe:2.3:o:lenovo:thinkserver_ts450_bios:-:*:*:*:*:*:*:*", "matchCriteriaId": "625A809C-6816-44B2-AAD8-5113CEC4DE50" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_110_14ibr:-:*:*:*:*:*:*:*", "matchCriteriaId": "41B2983E-CAF9-4E6E-A4D4-F79AEF94CB84" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_110_15ibr:-:*:*:*:*:*:*:*", "matchCriteriaId": "4C896D60-612E-461D-A3C2-B3459EB0E238" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_b70_80:-:*:*:*:*:*:*:*", "matchCriteriaId": "C2E0AA9B-81C3-4D6C-88D0-65970C5682A8" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_e31_80:-:*:*:*:*:*:*:*", "matchCriteriaId": "8F834881-401E-4E32-99C8-00D6843330F1" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_e40_80:-:*:*:*:*:*:*:*", "matchCriteriaId": "9A4CA14A-A647-4B07-923F-AD7C12681B4D" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_e41_80:-:*:*:*:*:*:*:*", "matchCriteriaId": "204534AC-7376-4466-B598-3A25AB4AA377" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_e51_80:-:*:*:*:*:*:*:*", "matchCriteriaId": "CBF9B47C-D285-4E5A-AD07-A40C2AA5FECF" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_g40_80:-:*:*:*:*:*:*:*", "matchCriteriaId": "4D65DC1E-0491-4963-9462-5EAC25CD2830" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_g50_80:-:*:*:*:*:*:*:*", "matchCriteriaId": "D612750E-8B26-4148-AE1E-8A149A959297" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_g50_80_touch:-:*:*:*:*:*:*:*", "matchCriteriaId": "EBDA89B6-39CF-4198-9857-718DF5BA5847" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_ideapad_300_14ibr:-:*:*:*:*:*:*:*", "matchCriteriaId": "E2991E19-F9B2-4AFD-94A9-326BC43234A5" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_ideapad_300_14isk:-:*:*:*:*:*:*:*", "matchCriteriaId": "5CD27C15-9EED-4532-AD0A-CC4FC943FF8C" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_ideapad_300_15ibr:-:*:*:*:*:*:*:*", "matchCriteriaId": "D30B00BC-5F48-4BB1-9DD9-311A0BFE91A2" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_ideapad_300_15isk:-:*:*:*:*:*:*:*", "matchCriteriaId": "BD912317-0247-4BD0-BC69-69FE0B1B1195" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_ideapad_300_17isk:-:*:*:*:*:*:*:*", "matchCriteriaId": "8E935C4C-2C5F-4D5A-A212-79267C02B7E1" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_ideapad_510s_12isk:-:*:*:*:*:*:*:*", "matchCriteriaId": "470CEC61-3CA0-4821-8B32-2B41C5E832DB" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_k21_80:-:*:*:*:*:*:*:*", "matchCriteriaId": "3DD41CA0-862C-44ED-A865-3D9626B1B1C0" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_k41_80:-:*:*:*:*:*:*:*", "matchCriteriaId": "97FF7810-3A0A-436A-A88E-1ECFB61C0890" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_miix_710_12ikb:-:*:*:*:*:*:*:*", "matchCriteriaId": "73B2E2E2-A7DF-486C-B5B9-8D04CEC38AC5" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_xiaoxin_air_12:-:*:*:*:*:*:*:*", "matchCriteriaId": "7FB2BCC5-30DD-4C2D-8291-2982D2E4F382" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_yoga_510_14isk:-:*:*:*:*:*:*:*", "matchCriteriaId": "4B2887E6-82C6-4456-A3BF-E10CFFF4CE89" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_yoga_510_15isk:-:*:*:*:*:*:*:*", "matchCriteriaId": "D86ECF6E-2A92-470E-8D9A-5EEFA24AA944" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_yoga_710_11ikb:-:*:*:*:*:*:*:*", "matchCriteriaId": "6D1BC063-90B1-4737-A77C-376BF26E4D97" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_yoga_710_11isk:-:*:*:*:*:*:*:*", "matchCriteriaId": "8A363290-2FA0-4C73-A221-BA5EA342A667" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_yoga_900_13isk:-:*:*:*:*:*:*:*", "matchCriteriaId": "6C817782-1F17-449C-9678-3EFB85AB8B7D" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:notebook_yoga_900s_12isk:-:*:*:*:*:*:*:*", "matchCriteriaId": "E57E495B-36C1-4910-80EE-90665E0ABF0F" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:thinkserver_ts150:-:*:*:*:*:*:*:*", "matchCriteriaId": "41D3E3E1-5ED3-45F0-B823-190A8A1119C9" }, { "vulnerable": false, "criteria": "cpe:2.3:h:lenovo:thinkserver_ts450:-:*:*:*:*:*:*:*", "matchCriteriaId": "0A85E220-538C-4F31-9469-3B8069F1D1DB" } ] } ] } ], "references": [ { "url": "http://www.securityfocus.com/bid/94595", "source": "psirt@lenovo.com" }, { "url": "https://support.lenovo.com/us/en/solutions/LEN_9903", "source": "psirt@lenovo.com", "tags": [ "Vendor Advisory" ] } ] }