CVE-2021-3453 describes a vulnerability in select Lenovo Notebook, ThinkPad, and Desktop systems where BIOS modules lack Intel Boot Guard protection. This flaw allows an attacker with physical access to write to the SPI flash storage. Rated Medium (CVSS 4.6), the vulnerability requires physical access (AV:P) but has low attack complexity (AC:L) and can lead to high integrity impact (I:H), potentially allowing persistent firmware modification. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it has received limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
n17etb4wCPE matchmatch criteria | cpe:2.3:o:lenovo:thinkpad_helix_firmware:n17etb4w:*:*:*:*:*:*:* | ||
n11et53wCPE matchmatch criteria | cpe:2.3:o:lenovo:thinkpad_t550_firmware:n11et53w:*:*:*:*:*:*:* | ||
n11et53wCPE matchmatch criteria | cpe:2.3:o:lenovo:thinkpad_w550s_firmware:n11et53w:*:*:*:*:*:*:* | ||
n14et55wCPE matchmatch criteria | cpe:2.3:o:lenovo:thinkpad_x1_carbon_3rd_gen_firmware:n14et55w:*:*:*:*:*:*:* | ||
n10et62wCPE matchmatch criteria | cpe:2.3:o:lenovo:thinkpad_x250_firmware:n10et62w:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.