TROYANOSYVIRUS
Back to CVEs

CVE-2018-9069

MEDIUM
5.9

Description

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.

CVE Details

CVSS v3.1 Score5.9
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredHIGH
User InteractionNONE
Published10/2/2018
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

hp:310s-14iskhp:310s-14isk_firmwarehp:320-15ikbrahp:320-15ikbra_firmwarehp:320-15ikbrnhp:320-15ikbrn_firmwarehp:320-15ikbrn_touchhp:320-15ikbrn_touch_firmwarehp:320-17ikbrnhp:320s-14ikbhp:320s-15ikbhp:320s-15ikb_firmwarehp:320s-15iskhp:320s-15isk_firmwarehp:510s-14iskhp:510s-14isk_firmwarehp:520-15ikbrnhp:520-15ikbrn_firmwarehp:520s-14ikbhp:520s-14ikb_firmwarehp:7000-15_u42hp:7000-15_u42_firmwarehp:7000_u42hp:7000_u42_firmwarehp:710s_plus-13ikb_16ghp:710s_plus-13ikb_16g_firmwarehp:710s_plus-3ikbhp:710s_plus-3ikb_firmwarehp:710s_plus_touch-13ikbhp:710s_plus_touch-13ikb_firmwarehp:720s-13ikbhp:720s-13ikb_firmwarehp:b320-14ikbhp:b320-14ikb_firmwarehp:e42-80hp:e43-80_kblhp:e43-80_kbl_firmwarehp:e52-80hp:flex_4-1470hp:flex_4-1470_firmwarehp:flex_5-1470hp:flex_5-1470_firmwarehp:flex_5-1570hp:flex_5-1570_firmwarehp:ideapad_2in1_14hp:ideapad_2in1_14_firmwarehp:lenovo_ideapad_320-14ikb\(i\+a\)hp:lenovo_ideapad_320-14ikb\(i\+a\)_firmwarehp:lenovo_ideapad_320-14ikb\(i\+n\)hp:lenovo_ideapad_320-14ikb\(i\+n\)_firmwarehp:lenovo_ideapad_320-15abrhp:lenovo_ideapad_320-15abr_firmwarehp:lenovo_ideapad_320-15ikb\(i\+n\)hp:lenovo_ideapad_320-15ikb\(i\+n\)_firmwarehp:lenovo_ideapad_320s-14ikbrhp:lenovo_ideapad_320s-14ikbr_firmwarehp:lenovo_ideapad_320s-15ikbrhp:lenovo_ideapad_320s-15ikbr_firmwarehp:lenovo_ideapad_520s-14ikbrhp:lenovo_ideapad_520s-14ikbr_firmwarehp:lenovo_ideapad_720s-14ikbhp:lenovo_ideapad_720s-14ikb_firmwarehp:lenovo_ideapad_flex_5-1470hp:lenovo_ideapad_flex_5-1470_firmwarehp:lenovo_ideapad_flex_5-1570hp:lenovo_ideapad_flex_5-1570_firmwarehp:lenovo_ideapad_y520-15ikbnhp:lenovo_ideapad_y520-15ikbn_firmwarehp:lenovo_tianyi_310-14ikbhp:lenovo_tianyi_310-14ikb_firmwarehp:lenovo_tianyi_310-15ikbhp:lenovo_tianyi_310-15ikb_firmwarehp:lenovo_v720-14hp:lenovo_v720-14_firmwarehp:lenovo_y520-15ikbahp:lenovo_y520-15ikba_firmwarehp:lenovo_y520-15ikbmhp:lenovo_y520-15ikbm_firmwarehp:lenovo_y720-15ikbhp:lenovo_y720-15ikb_firmwarehp:lenovo_yoga_520-14ikbhp:lenovo_yoga_520-14ikb_firmwarehp:lenovo_yoga_520-15ikbhp:lenovo_yoga_520-15ikb_firmwarehp:miix_720-12ikbhp:nano110-14ikbhp:nano110-14ikb_firmwarehp:nano110-15ikbhp:nano110-15ikb_firmwarehp:r720-15ikbahp:r720-15ikba_firmwarehp:r720-15ikbnhp:r720-15ikbn_firmwarehp:rescuer_r720-15ikbmhp:rescuer_r720-15ikbm_firmwarehp:rescuer_y520-15ikbmhp:rescuer_y520-15ikbm_firmwarehp:v310-14ikbhp:v310-14iskhp:v310-15ikbhp:v310-15iskhp:v330-14ikbhp:v330-14ikb_firmwarehp:v330-14iskhp:v330-14isk_firmwarehp:v510-14ikbhp:v510-15ikbhp:xiaoxinair13ikbprohp:xiaoxinair13ikbpro_firmwarehp:y520-15ikbahp:y520-15ikba_firmwarehp:y520-15ikbnhp:y520-15ikbn_firmwarehp:y720-15ikbhp:y720-15ikb_firmwarehp:yoga_310-11iaphp:yoga_310-11iap_firmwarehp:yoga_510-14iskhp:yoga_510-14isk_firmwarehp:yoga_720-13ikbhp:yoga_720-13ikb_firmwarehp:yoga_720-13ikbrhp:yoga_720-13ikbr_firmwarehp:yoga_720-15ikbhp:yoga_720-15ikb_firmwarelenovo:e42-80_firmwarelenovo:e52-80_firmwarelenovo:v310-14ikb_firmwarelenovo:v310-14isk_firmwarelenovo:v310-15ikb_firmwarelenovo:v310-15isk_firmwarelenovo:v510-14ikb_firmwarelenovo:v510-15ikb_firmware

Weaknesses (CWE)

CWE-362

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.