Security features bypass in Lenovo products - CVE-2023-5078
Published: October 13, 2023
Vulnerability identifier: #VU81984
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5078
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to compromise the affected system.
The vulnerability exists due to unspecified error in the BIOS of some Lenovo ThinkPad products. An attacker with physical access to device can tamper with BIOS firmware.
Affected software
ThinkPad P16s Gen 1 21CK
ThinkPad X13 Gen 3 21CM 21CN
ThinkPad S2 Yoga Gen 6 Type 21AG China Only
ThinkPad S2 Gen 8 Types 21FT Chine Only
ThinkPad S2 Gen 6 Type 21AF China Only
ThinkPad T16 Gen 1 21CJ
ThinkPad T16 Gen 1 21CH
ThinkPad T14s Gen 3 21CQ 21CR
ThinkPad T14 Gen 3 21CG
ThinkPad T14 Gen 3 21CF
ThinkPad P16s Gen 1 21CL
ThinkPad S2 Yoga Gen 8 Types 21FU China Only
ThinkPad P14s Gen 3 21J6
ThinkPad P14s Gen 3 21J5
ThinkPad L13 Yoga Gen 4 21FS
ThinkPad L13 Yoga Gen 4 21FR
ThinkPad L13 Yoga Gen 2 21AE s
ThinkPad L13 Yoga Gen 2 21AD s
ThinkPad L13 Gen 4 21FQ
ThinkPad L13 Gen 4 21FN
ThinkPad L13 Gen 2 21AC s
ThinkPad L13 Gen 2 21AB s
ThinkPad L14 Gen 4 21H5 s
ThinkPad L14 Gen 4 21H6 s
ThinkPad L15 Gen 4 21H7 s
ThinkPad L15 Gen 4 21H8 s
ThinkPad L13 Gen 3 21B9 21BA
ThinkPad L13 Yoga Gen 3 21BB
ThinkPad L13 Yoga Gen 3 21BC
ThinkPad S2 Gen 7 Type 21BD
ThinkPad S2 Yoga Gen 7 Type 21BE
ThinkPad L14 Gen 3 21C5 s
ThinkPad L14 Gen 3 21C6 s
ThinkPad L15 Gen 3 21C7 s
ThinkPad L15 Gen 3 21C8 s
ThinkPad X13 Gen 3 21CM 21CN
ThinkPad S2 Yoga Gen 6 Type 21AG China Only
ThinkPad S2 Gen 8 Types 21FT Chine Only
ThinkPad S2 Gen 6 Type 21AF China Only
ThinkPad T16 Gen 1 21CJ
ThinkPad T16 Gen 1 21CH
ThinkPad T14s Gen 3 21CQ 21CR
ThinkPad T14 Gen 3 21CG
ThinkPad T14 Gen 3 21CF
ThinkPad P16s Gen 1 21CL
ThinkPad S2 Yoga Gen 8 Types 21FU China Only
ThinkPad P14s Gen 3 21J6
ThinkPad P14s Gen 3 21J5
ThinkPad L13 Yoga Gen 4 21FS
ThinkPad L13 Yoga Gen 4 21FR
ThinkPad L13 Yoga Gen 2 21AE s
ThinkPad L13 Yoga Gen 2 21AD s
ThinkPad L13 Gen 4 21FQ
ThinkPad L13 Gen 4 21FN
ThinkPad L13 Gen 2 21AC s
ThinkPad L13 Gen 2 21AB s
ThinkPad L14 Gen 4 21H5 s
ThinkPad L14 Gen 4 21H6 s
ThinkPad L15 Gen 4 21H7 s
ThinkPad L15 Gen 4 21H8 s
ThinkPad L13 Gen 3 21B9 21BA
ThinkPad L13 Yoga Gen 3 21BB
ThinkPad L13 Yoga Gen 3 21BC
ThinkPad S2 Gen 7 Type 21BD
ThinkPad S2 Yoga Gen 7 Type 21BE
ThinkPad L14 Gen 3 21C5 s
ThinkPad L14 Gen 3 21C6 s
ThinkPad L15 Gen 3 21C7 s
ThinkPad L15 Gen 3 21C8 s
How to mitigate CVE-2023-5078
Install updates from vendor's website.
ThinkPad L14 Gen 4 21H5 s - update to 1.10
ThinkPad L14 Gen 4 21H6 s - update to 1.10
ThinkPad L15 Gen 4 21H7 s - update to 1.10
ThinkPad L15 Gen 4 21H8 s - update to 1.10
ThinkPad L13 Gen 3 21B9 21BA - update to 1.19
ThinkPad L13 Yoga Gen 3 21BB - update to 1.19
ThinkPad L13 Yoga Gen 3 21BC - update to 1.19
ThinkPad S2 Gen 7 Type 21BD - update to 1.19
ThinkPad S2 Yoga Gen 7 Type 21BE - update to 1.19
ThinkPad L14 Gen 3 21C5 s - update to 1.23
ThinkPad L14 Gen 3 21C6 s - update to 1.23
ThinkPad L15 Gen 3 21C7 s - update to 1.23
ThinkPad L15 Gen 3 21C8 s - update to 1.23
ThinkPad L14 Gen 4 21H6 s - update to 1.10
ThinkPad L15 Gen 4 21H7 s - update to 1.10
ThinkPad L15 Gen 4 21H8 s - update to 1.10
ThinkPad L13 Gen 3 21B9 21BA - update to 1.19
ThinkPad L13 Yoga Gen 3 21BB - update to 1.19
ThinkPad L13 Yoga Gen 3 21BC - update to 1.19
ThinkPad S2 Gen 7 Type 21BD - update to 1.19
ThinkPad S2 Yoga Gen 7 Type 21BE - update to 1.19
ThinkPad L14 Gen 3 21C5 s - update to 1.23
ThinkPad L14 Gen 3 21C6 s - update to 1.23
ThinkPad L15 Gen 3 21C7 s - update to 1.23
ThinkPad L15 Gen 3 21C8 s - update to 1.23