CVE-2019-6171: Lenovo 20a7 Firmware
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
Affected products
- Lenovo 20a7 Firmware: affected versions not specified
- Lenovo 20a8 Firmware: affected versions not specified
- Lenovo 20a9 Firmware: affected versions not specified
- Lenovo 20aa Firmware: affected versions not specified
- Lenovo 20ab Firmware: affected versions not specified
- Lenovo 20ac Firmware: affected versions not specified
- Lenovo 20aj Firmware: affected versions not specified
- Lenovo 20ak Firmware: affected versions not specified
- Lenovo 20al Firmware: affected versions not specified
- Lenovo 20am Firmware: affected versions not specified
- Lenovo 20an Firmware: affected versions not specified
- Lenovo 20aq Firmware: affected versions not specified
- Lenovo 20ar Firmware: affected versions not specified
- Lenovo 20aw Firmware: affected versions not specified
- Lenovo 20b0 Firmware: affected versions not specified
- Lenovo 20b3 Firmware: affected versions not specified
- Lenovo 20b6 Firmware: affected versions not specified
- Lenovo 20b7 Firmware: affected versions not specified
- Lenovo 20be Firmware: affected versions not specified
- Lenovo 20bf Firmware: affected versions not specified
- Lenovo 20bg Firmware: affected versions not specified
- Lenovo 20bl Firmware: affected versions not specified
- Lenovo 20bm Firmware: affected versions not specified
- Lenovo 20bu Firmware: affected versions not specified
- Lenovo 20bv Firmware: affected versions not specified
- and 123 more
Published 2019-08-19. Last modified 2026-06-17.