// For flags

CVE-2020-8336

 

Severity Score

6.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.

Lenovo implementó protecciones de Intel CSME Anti-rollback ARB en algunos modelos ThinkPad para impedir la reversión del Firmware CSME en flash

*Credits: Lenovo thanks Maxim Goryachy & Mark Ermolov of Positive Technologies
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Physical
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-28 CVE Reserved
  • 2020-06-09 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Lenovo
Search vendor "Lenovo"
Thinkpad E14 Firmware
Search vendor "Lenovo" for product "Thinkpad E14 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad E14 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad E14
Search vendor "Lenovo" for product "Thinkpad E14"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad E15 Firmware
Search vendor "Lenovo" for product "Thinkpad E15 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad E15 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad E15
Search vendor "Lenovo" for product "Thinkpad E15"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad R14 Firmware
Search vendor "Lenovo" for product "Thinkpad R14 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad R14 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad R14
Search vendor "Lenovo" for product "Thinkpad R14"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad S3 Gen 2 Firmware
Search vendor "Lenovo" for product "Thinkpad S3 Gen 2 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad S3 Gen 2 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad S3 Gen 2
Search vendor "Lenovo" for product "Thinkpad S3 Gen 2"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad E490s Firmware
Search vendor "Lenovo" for product "Thinkpad E490s Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad E490s Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad E490s
Search vendor "Lenovo" for product "Thinkpad E490s"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad S3 Firmware
Search vendor "Lenovo" for product "Thinkpad S3 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad S3 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad S3
Search vendor "Lenovo" for product "Thinkpad S3"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad E490 Firmware
Search vendor "Lenovo" for product "Thinkpad E490 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad E490 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad E490
Search vendor "Lenovo" for product "Thinkpad E490"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad E590 Firmware
Search vendor "Lenovo" for product "Thinkpad E590 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad E590 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad E590
Search vendor "Lenovo" for product "Thinkpad E590"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad R490 Firmware
Search vendor "Lenovo" for product "Thinkpad R490 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad R490 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad R490
Search vendor "Lenovo" for product "Thinkpad R490"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad R590 Firmware
Search vendor "Lenovo" for product "Thinkpad R590 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad R590 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad R590
Search vendor "Lenovo" for product "Thinkpad R590"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad L13 1st Gen Firmware
Search vendor "Lenovo" for product "Thinkpad L13 1st Gen Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad L13 1st Gen Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad L13 1st Gen
Search vendor "Lenovo" for product "Thinkpad L13 1st Gen"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad L1415 Gen 1 Firmware
Search vendor "Lenovo" for product "Thinkpad L1415 Gen 1 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad L1415 Gen 1 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad L1415 Gen 1
Search vendor "Lenovo" for product "Thinkpad L1415 Gen 1"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad L390 Yoga Firmware
Search vendor "Lenovo" for product "Thinkpad L390 Yoga Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad L390 Yoga Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad L390 Yoga
Search vendor "Lenovo" for product "Thinkpad L390 Yoga"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad S2 Yoga 4th Gen Firmware
Search vendor "Lenovo" for product "Thinkpad S2 Yoga 4th Gen Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad S2 Yoga 4th Gen Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad S2 Yoga 4th Gen
Search vendor "Lenovo" for product "Thinkpad S2 Yoga 4th Gen"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad L490 Firmware
Search vendor "Lenovo" for product "Thinkpad L490 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad L490 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad L490
Search vendor "Lenovo" for product "Thinkpad L490"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad L590 Firmware
Search vendor "Lenovo" for product "Thinkpad L590 Firmware"
< 2020-07-10
Search vendor "Lenovo" for product "Thinkpad L590 Firmware" and version " < 2020-07-10"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad L590
Search vendor "Lenovo" for product "Thinkpad L590"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad P1 \(20mx\) Firmware
Search vendor "Lenovo" for product "Thinkpad P1 \(20mx\) Firmware"
< n2eet47w
Search vendor "Lenovo" for product "Thinkpad P1 \(20mx\) Firmware" and version " < n2eet47w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad P1 \(20mx\)
Search vendor "Lenovo" for product "Thinkpad P1 \(20mx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad P1 \(20qx\) Firmware
Search vendor "Lenovo" for product "Thinkpad P1 \(20qx\) Firmware"
< n2oet44w
Search vendor "Lenovo" for product "Thinkpad P1 \(20qx\) Firmware" and version " < n2oet44w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad P1 \(20qx\)
Search vendor "Lenovo" for product "Thinkpad P1 \(20qx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad P43s \(20rx\) Firmware
Search vendor "Lenovo" for product "Thinkpad P43s \(20rx\) Firmware"
< n2iet88w
Search vendor "Lenovo" for product "Thinkpad P43s \(20rx\) Firmware" and version " < n2iet88w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad P43s \(20rx\)
Search vendor "Lenovo" for product "Thinkpad P43s \(20rx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad P52 \(20mx\) Firmware
Search vendor "Lenovo" for product "Thinkpad P52 \(20mx\) Firmware"
< n2cet51w-1.34
Search vendor "Lenovo" for product "Thinkpad P52 \(20mx\) Firmware" and version " < n2cet51w-1.34"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad P52 \(20mx\)
Search vendor "Lenovo" for product "Thinkpad P52 \(20mx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad P53 \(20qx\) Firmware
Search vendor "Lenovo" for product "Thinkpad P53 \(20qx\) Firmware"
< n2net37w
Search vendor "Lenovo" for product "Thinkpad P53 \(20qx\) Firmware" and version " < n2net37w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad P53 \(20qx\)
Search vendor "Lenovo" for product "Thinkpad P53 \(20qx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad P53s \(20nx\) Firmware
Search vendor "Lenovo" for product "Thinkpad P53s \(20nx\) Firmware"
< n2iet88w
Search vendor "Lenovo" for product "Thinkpad P53s \(20nx\) Firmware" and version " < n2iet88w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad P53s \(20nx\)
Search vendor "Lenovo" for product "Thinkpad P53s \(20nx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad P72 \(20mx\) Firmware
Search vendor "Lenovo" for product "Thinkpad P72 \(20mx\) Firmware"
< n2cet51w
Search vendor "Lenovo" for product "Thinkpad P72 \(20mx\) Firmware" and version " < n2cet51w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad P72 \(20mx\)
Search vendor "Lenovo" for product "Thinkpad P72 \(20mx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad P73 \(20qx\) Firmware
Search vendor "Lenovo" for product "Thinkpad P73 \(20qx\) Firmware"
< n2net37w
Search vendor "Lenovo" for product "Thinkpad P73 \(20qx\) Firmware" and version " < n2net37w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad P73 \(20qx\)
Search vendor "Lenovo" for product "Thinkpad P73 \(20qx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad T490 \(20nx\) Firmware
Search vendor "Lenovo" for product "Thinkpad T490 \(20nx\) Firmware"
< n2iet88w
Search vendor "Lenovo" for product "Thinkpad T490 \(20nx\) Firmware" and version " < n2iet88w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad T490 \(20nx\)
Search vendor "Lenovo" for product "Thinkpad T490 \(20nx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad T490 \(20qx\) Firmware
Search vendor "Lenovo" for product "Thinkpad T490 \(20qx\) Firmware"
< n2iet88w
Search vendor "Lenovo" for product "Thinkpad T490 \(20qx\) Firmware" and version " < n2iet88w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad T490 \(20qx\)
Search vendor "Lenovo" for product "Thinkpad T490 \(20qx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad T490 \(20rx\) Firmware
Search vendor "Lenovo" for product "Thinkpad T490 \(20rx\) Firmware"
< n2iet88w
Search vendor "Lenovo" for product "Thinkpad T490 \(20rx\) Firmware" and version " < n2iet88w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad T490 \(20rx\)
Search vendor "Lenovo" for product "Thinkpad T490 \(20rx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad T490s \(20nx\) Firmware
Search vendor "Lenovo" for product "Thinkpad T490s \(20nx\) Firmware"
< n2jet87w
Search vendor "Lenovo" for product "Thinkpad T490s \(20nx\) Firmware" and version " < n2jet87w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad T490s \(20nx\)
Search vendor "Lenovo" for product "Thinkpad T490s \(20nx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad T590 \(20nx\) Firmware
Search vendor "Lenovo" for product "Thinkpad T590 \(20nx\) Firmware"
< n2iet88w
Search vendor "Lenovo" for product "Thinkpad T590 \(20nx\) Firmware" and version " < n2iet88w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad T590 \(20nx\)
Search vendor "Lenovo" for product "Thinkpad T590 \(20nx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad X1 Carbon \(20qx\) Firmware
Search vendor "Lenovo" for product "Thinkpad X1 Carbon \(20qx\) Firmware"
< n2het47w
Search vendor "Lenovo" for product "Thinkpad X1 Carbon \(20qx\) Firmware" and version " < n2het47w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad X1 Carbon \(20qx\)
Search vendor "Lenovo" for product "Thinkpad X1 Carbon \(20qx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad X1 Carbon \(20rx\) Firmware
Search vendor "Lenovo" for product "Thinkpad X1 Carbon \(20rx\) Firmware"
< n2het47w
Search vendor "Lenovo" for product "Thinkpad X1 Carbon \(20rx\) Firmware" and version " < n2het47w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad X1 Carbon \(20rx\)
Search vendor "Lenovo" for product "Thinkpad X1 Carbon \(20rx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad X1 Extreme \(20mx\) Firmware
Search vendor "Lenovo" for product "Thinkpad X1 Extreme \(20mx\) Firmware"
< n2eet47w
Search vendor "Lenovo" for product "Thinkpad X1 Extreme \(20mx\) Firmware" and version " < n2eet47w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad X1 Extreme \(20mx\)
Search vendor "Lenovo" for product "Thinkpad X1 Extreme \(20mx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad X1 Extreme \(20qx\) Firmware
Search vendor "Lenovo" for product "Thinkpad X1 Extreme \(20qx\) Firmware"
< n2oet44w
Search vendor "Lenovo" for product "Thinkpad X1 Extreme \(20qx\) Firmware" and version " < n2oet44w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad X1 Extreme \(20qx\)
Search vendor "Lenovo" for product "Thinkpad X1 Extreme \(20qx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad X1 Yoga \(20qx\) Firmware
Search vendor "Lenovo" for product "Thinkpad X1 Yoga \(20qx\) Firmware"
< n2het47w
Search vendor "Lenovo" for product "Thinkpad X1 Yoga \(20qx\) Firmware" and version " < n2het47w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad X1 Yoga \(20qx\)
Search vendor "Lenovo" for product "Thinkpad X1 Yoga \(20qx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad X1 Yoga \(20sx\) Firmware
Search vendor "Lenovo" for product "Thinkpad X1 Yoga \(20sx\) Firmware"
< n2het47w
Search vendor "Lenovo" for product "Thinkpad X1 Yoga \(20sx\) Firmware" and version " < n2het47w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad X1 Yoga \(20sx\)
Search vendor "Lenovo" for product "Thinkpad X1 Yoga \(20sx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad X390 \(20qx\) Firmware
Search vendor "Lenovo" for product "Thinkpad X390 \(20qx\) Firmware"
< n2jet87w
Search vendor "Lenovo" for product "Thinkpad X390 \(20qx\) Firmware" and version " < n2jet87w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad X390 \(20qx\)
Search vendor "Lenovo" for product "Thinkpad X390 \(20qx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad X390 \(20sx\) Firmware
Search vendor "Lenovo" for product "Thinkpad X390 \(20sx\) Firmware"
< n2set18w
Search vendor "Lenovo" for product "Thinkpad X390 \(20sx\) Firmware" and version " < n2set18w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad X390 \(20sx\)
Search vendor "Lenovo" for product "Thinkpad X390 \(20sx\)"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkpad X390 Yoga Firmware
Search vendor "Lenovo" for product "Thinkpad X390 Yoga Firmware"
< n2let74w
Search vendor "Lenovo" for product "Thinkpad X390 Yoga Firmware" and version " < n2let74w"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkpad X390 Yoga
Search vendor "Lenovo" for product "Thinkpad X390 Yoga"
--
Safe