QSearchQSearch

CVE-2021-3614

6.4 MEDIUM

A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges unde...

Published: 2021-07-16 · Last updated: 2026-06-17

Severity and scoring

CVSS
6.4 MEDIUM
Vector
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-636

Affected products

VendorProduct
lenovo100e_2nd_gen_firmware, 300e_2nd_gen_firmware, ideapad_1-11ada05_firmware

Description

A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain conditions during a BIOS update performed by Lenovo Vantage.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2025-13454 A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to ... (5.5 MEDIUM)
  • CVE-2025-13453 A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on t... (4.6 MEDIUM)
  • CVE-2022-0354 A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute ... (7.3 HIGH)
  • CVE-2021-3633 A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation (7.3 HIGH)
  • CVE-2021-3617 A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted net... (7.2 HIGH)

Same CWE

  • CVE-2026-53852 OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to r... (5.4 MEDIUM)
  • CVE-2026-53837 OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel ty... (3.7 LOW)
  • CVE-2026-49318 Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows ... (2.4 LOW)
  • CVE-2026-49317 Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows ... (2.4 LOW)
  • CVE-2026-42246 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby (7.4 HIGH)