2024-12-08 03:06:42 +00:00

214 lines
7.4 KiB
JSON

{
"id": "CVE-2017-3754",
"sourceIdentifier": "psirt@lenovo.com",
"published": "2017-07-17T19:29:00.323",
"lastModified": "2024-11-21T03:26:04.527",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code."
},
{
"lang": "es",
"value": "Algunos sistemas notebook de la marca Lenovo no tienen protecciones de escritura configuradas apropiadamente en el BIOS del sistema. Esto podr\u00eda permitir a un atacante con acceso f\u00edsico o administrativo a un sistema para ser capaz de flashear el BIOS con una imagen arbitraria y potencialmente ejecutar c\u00f3digo BIOS malicioso."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 6.7,
"baseSeverity": "MEDIUM",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 0.8,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"baseScore": 7.2,
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 3.9,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:lenovo:bios:-:*:*:*:*:*:*:*",
"matchCriteriaId": "61D66F0D-6C60-4CF6-A509-C6FAC2E22F95"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:710s-13ikb\\/xiaoxin_air_13ikb:-:*:*:*:*:*:*:*",
"matchCriteriaId": "CF203824-4977-4970-93FA-311FC0726DE8"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:710s-13isk\\/xiaoxin_air_13:-:*:*:*:*:*:*:*",
"matchCriteriaId": "FA559DCA-5395-4205-916B-62A94E078788"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:k21-80:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E56C7CE7-D4A0-4179-B65D-EA8EDA2F7299"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:k22-80\\/lenovo_v720-12:-:*:*:*:*:*:*:*",
"matchCriteriaId": "6817BA2D-2383-428F-941D-BCAC7A476818"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:k41-80:-:*:*:*:*:*:*:*",
"matchCriteriaId": "BDC9595C-D1DA-4769-9401-1D2430CE69CE"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:lenovo_ideapad_110-14ast:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E63C6054-D0EE-4AED-B829-A2F676E89D86"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:lenovo_ideapad_110-15ast:-:*:*:*:*:*:*:*",
"matchCriteriaId": "3E3F252A-E00B-40AA-8F02-7987D2102D4D"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:lenovo_ideapad_320-14ast:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0BD8431A-FFF2-4519-BCC3-80A8B76CC80E"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:lenovo_ideapad_320-15ast:-:*:*:*:*:*:*:*",
"matchCriteriaId": "21481398-B4A5-4C7F-BA4F-A52D6C13756B"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:lenovo_xiaoxin_rui7000:-:*:*:*:*:*:*:*",
"matchCriteriaId": "94BA3B3C-0E21-4877-8B0D-11E5FEF12384"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:miix_710-12ikb:-:*:*:*:*:*:*:*",
"matchCriteriaId": "9BE26E1F-D6B8-4ECD-86DE-D492BBC1FE64"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:miix_720-12ikb:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D0E7697B-53B4-4A2A-B285-0620962A0E4A"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:notebook_320-17ast:-:*:*:*:*:*:*:*",
"matchCriteriaId": "719BD6FE-DB95-4096-9829-33536AD077C8"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:rescuer_e520-15ikb:-:*:*:*:*:*:*:*",
"matchCriteriaId": "9CC1D30D-C105-4BAF-9085-7E5C8D253A23"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:v110-14iap:-:*:*:*:*:*:*:*",
"matchCriteriaId": "FAED167E-15AF-4B45-952C-113726BCFAE0"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:v110-15iap:-:*:*:*:*:*:*:*",
"matchCriteriaId": "972B1468-D71C-449C-B392-4A62BA9BF835"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:v110-15ikb:-:*:*:*:*:*:*:*",
"matchCriteriaId": "9423385C-5562-4578-9602-C85ED87CB530"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:v110-15isk:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B7C41B17-C208-4A3A-BCC5-F7D4046A9249"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:lenovo:yoga_710-11ikb:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A573B96D-E21C-4869-A6CE-FDB3926875CB"
}
]
}
]
}
],
"references": [
{
"url": "https://support.lenovo.com/us/en/product_security/LEN-15084",
"source": "psirt@lenovo.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://support.lenovo.com/us/en/product_security/LEN-15084",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
}
]
}