CVE-2020-8353
moderate-risk
Published 2020-11-11
Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.
Do I need to act?
-
0.05% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.7/10
Medium
LOCAL
/ LOW complexity
Affected Products (14)
Thinkcentre M910Z Firmware
Thinkcentre M920S Firmware
Thinkcentre M920T Firmware
Thinkcentre M920Q Firmware
Thinkcentre M920Z Firmware
Thinkstation P330T Firmware
Thinkstation P330S Firmware
Thinkstation P330 Tiny Firmware
Thinkstation P340T Firmware
Thinkstation P340S Firmware
Affected Vendors
References (2)
39
/ 100
moderate-risk
Severity
21/34 · High
Exploitability
0/34 · Minimal
Exposure
18/34 · Moderate