CVE-2016-5247 describes a critical vulnerability in the BIOS of numerous Lenovo ThinkCentre, ThinkServer, and ThinkStation devices, allowing local or physically proximate attackers to bypass Secure Boot. This bypass is achieved by exploiting an embedded AMI test key, compromising the integrity of the boot process. With a CVSS score of 7.8 (High), this vulnerability presents a significant risk, enabling attackers with local access to achieve high impact on confidentiality, integrity, and availability. The attack complexity is low, requiring only local user privileges or physical proximity. While there is no evidence of active exploitation (not in KEV), no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion, the vulnerability received media coverage, indicating its potential significance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:lenovo:bios:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.