CVE-2019-6171: Lenovo 20a7 Firmware

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.

Affected products

  • Lenovo 20a7 Firmware: affected versions not specified
  • Lenovo 20a8 Firmware: affected versions not specified
  • Lenovo 20a9 Firmware: affected versions not specified
  • Lenovo 20aa Firmware: affected versions not specified
  • Lenovo 20ab Firmware: affected versions not specified
  • Lenovo 20ac Firmware: affected versions not specified
  • Lenovo 20aj Firmware: affected versions not specified
  • Lenovo 20ak Firmware: affected versions not specified
  • Lenovo 20al Firmware: affected versions not specified
  • Lenovo 20am Firmware: affected versions not specified
  • Lenovo 20an Firmware: affected versions not specified
  • Lenovo 20aq Firmware: affected versions not specified
  • Lenovo 20ar Firmware: affected versions not specified
  • Lenovo 20aw Firmware: affected versions not specified
  • Lenovo 20b0 Firmware: affected versions not specified
  • Lenovo 20b3 Firmware: affected versions not specified
  • Lenovo 20b6 Firmware: affected versions not specified
  • Lenovo 20b7 Firmware: affected versions not specified
  • Lenovo 20be Firmware: affected versions not specified
  • Lenovo 20bf Firmware: affected versions not specified
  • Lenovo 20bg Firmware: affected versions not specified
  • Lenovo 20bl Firmware: affected versions not specified
  • Lenovo 20bm Firmware: affected versions not specified
  • Lenovo 20bu Firmware: affected versions not specified
  • Lenovo 20bv Firmware: affected versions not specified
  • and 123 more

Published 2019-08-19. Last modified 2026-06-17.