CVE-2021-3970 is a local privilege escalation vulnerability in the LenovoVariable SMI Handler within the BIOS of certain Lenovo Notebook models. It allows an attacker with local access and elevated privileges to execute arbitrary code due to insufficient validation. The vulnerability has a CVSS score of 6.7 (Medium), indicating high impact on confidentiality, integrity, and availability, with low attack complexity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, suggesting awareness among researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< e8cn33wwCPE matchmatch criteria | cpe:2.3:o:lenovo:ideapad_3-14ada05_firmware:*:*:*:*:*:*:*:* | ||
< hbcn21wwCPE matchmatch criteria | cpe:2.3:o:lenovo:ideapad_3-14ada6_firmware:*:*:*:*:*:*:*:* | ||
< glcn43wwCPE matchmatch criteria | cpe:2.3:o:lenovo:ideapad_3-14alc6_firmware:*:*:*:*:*:*:*:* | ||
< dzcn42wwCPE matchmatch criteria | cpe:2.3:o:lenovo:ideapad_3-14are05_firmware:*:*:*:*:*:*:*:* | ||
< hbcn21wwCPE matchmatch criteria | cpe:2.3:o:lenovo:ideapad_3-15ada6_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.