CVE-2018-9069

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hp:310s-14isk_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:310s-14isk:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hp:320-15ikbra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:320-15ikbra:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hp:320-15ikbrn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:320-15ikbrn:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hp:320-15ikbrn_touch_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:320-15ikbrn_touch:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:hp:320-17ikbrn:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:320-17ikbrn:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:h:hp:320s-14ikb:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:320s-14ikb:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hp:320s-15ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:320s-15ikb:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hp:320s-15isk_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:320s-15isk:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hp:510s-14isk_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:510s-14isk:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hp:520-15ikbrn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:520-15ikbrn:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:hp:520s-14ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:520s-14ikb:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:hp:710s_plus-13ikb_16g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:710s_plus-13ikb_16g:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:hp:710s_plus-3ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:710s_plus-3ikb:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:hp:xiaoxinair13ikbpro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:xiaoxinair13ikbpro:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:hp:710s_plus_touch-13ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:710s_plus_touch-13ikb:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:hp:720s-13ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:720s-13ikb:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:hp:b320-14ikb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:b320-14ikb:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:lenovo:e42-80_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:e42-80:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:lenovo:e52-80_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:e52-80:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:hp:flex_4-1470_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:flex_4-1470:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:hp:flex_5-1470_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:flex_5-1470:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:hp:flex_5-1570_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:flex_5-1570:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:hp:ideapad_2in1_14_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:ideapad_2in1_14:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:hp:lenovo_ideapad_320-14ikb\(i\+a\)_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_ideapad_320-14ikb\(i\+a\):-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:hp:lenovo_ideapad_320-14ikb\(i\+n\)_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_ideapad_320-14ikb\(i\+n\):-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:hp:lenovo_ideapad_320-15abr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_ideapad_320-15abr:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:hp:lenovo_ideapad_320-15ikb\(i\+n\)_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_ideapad_320-15ikb\(i\+n\):-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:hp:lenovo_ideapad_320s-14ikbr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_ideapad_320s-14ikbr:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:hp:lenovo_ideapad_320s-15ikbr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_ideapad_320s-15ikbr:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:hp:lenovo_ideapad_520s-14ikbr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_ideapad_520s-14ikbr:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:hp:lenovo_ideapad_720s-14ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_ideapad_720s-14ikb:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:hp:lenovo_ideapad_flex_5-1470_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_ideapad_flex_5-1470:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:hp:lenovo_ideapad_flex_5-1570_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_ideapad_flex_5-1570:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:hp:lenovo_ideapad_y520-15ikbn_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_ideapad_y520-15ikbn:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:hp:lenovo_tianyi_310-14ikb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_tianyi_310-14ikb:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:hp:lenovo_tianyi_310-15ikb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_tianyi_310-15ikb:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:hp:lenovo_y520-15ikba_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_y520-15ikba:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:hp:lenovo_y520-15ikbm_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_y520-15ikbm:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:hp:lenovo_yoga_520-14ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_yoga_520-14ikb:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:hp:lenovo_yoga_520-15ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_yoga_520-15ikb:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:h:hp:miix_720-12ikb:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:miix_720-12ikb:-:*:*:*:*:*:*:*

Configuration 42 (hide)

AND
cpe:2.3:o:hp:nano110-14ikb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:nano110-14ikb:-:*:*:*:*:*:*:*

Configuration 43 (hide)

AND
cpe:2.3:o:hp:nano110-15ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:nano110-15ikb:-:*:*:*:*:*:*:*

Configuration 44 (hide)

AND
cpe:2.3:o:hp:rescuer_r720-15ikbm_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:rescuer_r720-15ikbm:-:*:*:*:*:*:*:*

Configuration 45 (hide)

AND
cpe:2.3:o:hp:rescuer_y520-15ikbm_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:rescuer_y520-15ikbm:-:*:*:*:*:*:*:*

Configuration 46 (hide)

AND
cpe:2.3:o:lenovo:v310-14ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:v310-14ikb:-:*:*:*:*:*:*:*

Configuration 47 (hide)

AND
cpe:2.3:o:lenovo:v310-14isk_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:v310-14isk:-:*:*:*:*:*:*:*

Configuration 48 (hide)

AND
cpe:2.3:o:lenovo:v310-15ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:v310-15ikb:-:*:*:*:*:*:*:*

Configuration 49 (hide)

AND
cpe:2.3:o:lenovo:v310-15isk_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:v310-15isk:-:*:*:*:*:*:*:*

Configuration 50 (hide)

AND
cpe:2.3:o:hp:v330-14ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:v330-14ikb:-:*:*:*:*:*:*:*

Configuration 51 (hide)

AND
cpe:2.3:o:hp:v330-14isk_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:v330-14isk:-:*:*:*:*:*:*:*

Configuration 52 (hide)

AND
cpe:2.3:o:lenovo:v510-14ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:v510-14ikb:-:*:*:*:*:*:*:*

Configuration 53 (hide)

AND
cpe:2.3:o:lenovo:v510-15ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:v510-15ikb:-:*:*:*:*:*:*:*

Configuration 54 (hide)

AND
cpe:2.3:o:hp:yoga_310-11iap_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:yoga_310-11iap:-:*:*:*:*:*:*:*

Configuration 55 (hide)

AND
cpe:2.3:o:hp:yoga_510-14isk_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:yoga_510-14isk:-:*:*:*:*:*:*:*

Configuration 56 (hide)

AND
cpe:2.3:o:hp:yoga_720-13ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:yoga_720-13ikb:-:*:*:*:*:*:*:*

Configuration 57 (hide)

AND
cpe:2.3:o:hp:yoga_720-13ikbr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:yoga_720-13ikbr:-:*:*:*:*:*:*:*

Configuration 58 (hide)

AND
cpe:2.3:o:hp:yoga_720-15ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:yoga_720-15ikb:-:*:*:*:*:*:*:*

Configuration 59 (hide)

AND
cpe:2.3:o:hp:lenovo_v720-14_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_v720-14:-:*:*:*:*:*:*:*

Configuration 60 (hide)

AND
cpe:2.3:o:hp:7000_u42_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:7000_u42:-:*:*:*:*:*:*:*

Configuration 61 (hide)

AND
cpe:2.3:o:hp:7000-15_u42_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:7000-15_u42:-:*:*:*:*:*:*:*

Configuration 62 (hide)

AND
cpe:2.3:o:hp:r720-15ikba_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:r720-15ikba:-:*:*:*:*:*:*:*

Configuration 63 (hide)

AND
cpe:2.3:o:hp:y520-15ikba_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:y520-15ikba:-:*:*:*:*:*:*:*

Configuration 64 (hide)

AND
cpe:2.3:o:hp:r720-15ikbn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:r720-15ikbn:-:*:*:*:*:*:*:*

Configuration 65 (hide)

AND
cpe:2.3:o:hp:y520-15ikbn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:y520-15ikbn:-:*:*:*:*:*:*:*

Configuration 66 (hide)

AND
cpe:2.3:o:hp:y720-15ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:y720-15ikb:-:*:*:*:*:*:*:*

Configuration 67 (hide)

AND
cpe:2.3:o:hp:lenovo_y720-15ikb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lenovo_y720-15ikb:-:*:*:*:*:*:*:*

Configuration 68 (hide)

AND
cpe:2.3:o:hp:e43-80_kbl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:e43-80_kbl:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:14

Type Values Removed Values Added
References () https://support.lenovo.com/us/en/solutions/LEN-20184 - Vendor Advisory () https://support.lenovo.com/us/en/solutions/LEN-20184 - Vendor Advisory

Information

Published : 2018-10-02 13:29

Updated : 2024-11-21 04:14


NVD link : CVE-2018-9069

Mitre link : CVE-2018-9069

CVE.ORG link : CVE-2018-9069


JSON object : View

Products Affected

hp

  • 710s_plus-13ikb_16g
  • ideapad_2in1_14
  • y720-15ikb_firmware
  • miix_720-12ikb
  • lenovo_tianyi_310-14ikb
  • r720-15ikba_firmware
  • rescuer_y520-15ikbm_firmware
  • y520-15ikbn
  • lenovo_ideapad_flex_5-1570_firmware
  • 510s-14isk
  • yoga_720-15ikb
  • v310-14ikb
  • 710s_plus_touch-13ikb_firmware
  • rescuer_r720-15ikbm
  • lenovo_ideapad_y520-15ikbn
  • 320-15ikbrn_firmware
  • yoga_720-15ikb_firmware
  • 710s_plus-3ikb_firmware
  • nano110-15ikb_firmware
  • flex_5-1570_firmware
  • flex_5-1470_firmware
  • lenovo_ideapad_320-15ikb\(i\+n\)_firmware
  • v510-15ikb
  • lenovo_ideapad_flex_5-1470_firmware
  • yoga_310-11iap_firmware
  • r720-15ikbn
  • 320s-15ikb_firmware
  • lenovo_ideapad_flex_5-1570
  • 7000_u42_firmware
  • v510-14ikb
  • 320s-15ikb
  • 710s_plus-3ikb
  • lenovo_v720-14_firmware
  • r720-15ikba
  • flex_4-1470_firmware
  • yoga_720-13ikb_firmware
  • 320-15ikbra_firmware
  • lenovo_ideapad_320-14ikb\(i\+n\)_firmware
  • 7000_u42
  • 320s-15isk
  • 7000-15_u42
  • lenovo_yoga_520-14ikb_firmware
  • lenovo_tianyi_310-14ikb_firmware
  • 320s-15isk_firmware
  • e43-80_kbl
  • 320s-14ikb
  • v330-14isk_firmware
  • e43-80_kbl_firmware
  • lenovo_ideapad_320-15ikb\(i\+n\)
  • 310s-14isk
  • rescuer_r720-15ikbm_firmware
  • lenovo_ideapad_320s-15ikbr_firmware
  • e42-80
  • lenovo_ideapad_320-14ikb\(i\+n\)
  • lenovo_y520-15ikba_firmware
  • 320-15ikbrn
  • yoga_510-14isk
  • 320-15ikbra
  • v310-15isk
  • nano110-14ikb_firmware
  • flex_4-1470
  • v310-14isk
  • xiaoxinair13ikbpro
  • lenovo_y720-15ikb
  • lenovo_ideapad_320-14ikb\(i\+a\)_firmware
  • 710s_plus-13ikb_16g_firmware
  • 720s-13ikb_firmware
  • 510s-14isk_firmware
  • e52-80
  • v330-14ikb_firmware
  • lenovo_y520-15ikbm
  • lenovo_y520-15ikba
  • 520s-14ikb
  • lenovo_ideapad_320-14ikb\(i\+a\)
  • 720s-13ikb
  • 310s-14isk_firmware
  • lenovo_tianyi_310-15ikb
  • lenovo_ideapad_320s-14ikbr
  • lenovo_ideapad_520s-14ikbr_firmware
  • xiaoxinair13ikbpro_firmware
  • lenovo_ideapad_720s-14ikb
  • y520-15ikba_firmware
  • r720-15ikbn_firmware
  • 520s-14ikb_firmware
  • yoga_720-13ikb
  • lenovo_ideapad_y520-15ikbn_firmware
  • v310-15ikb
  • 320-15ikbrn_touch
  • lenovo_yoga_520-15ikb_firmware
  • lenovo_y720-15ikb_firmware
  • lenovo_yoga_520-15ikb
  • lenovo_v720-14
  • y520-15ikbn_firmware
  • 520-15ikbrn
  • yoga_720-13ikbr_firmware
  • y520-15ikba
  • ideapad_2in1_14_firmware
  • b320-14ikb_firmware
  • nano110-15ikb
  • v330-14ikb
  • 710s_plus_touch-13ikb
  • 320-15ikbrn_touch_firmware
  • b320-14ikb
  • lenovo_ideapad_320s-14ikbr_firmware
  • yoga_720-13ikbr
  • 7000-15_u42_firmware
  • lenovo_ideapad_320-15abr
  • yoga_510-14isk_firmware
  • flex_5-1470
  • 320-17ikbrn
  • lenovo_y520-15ikbm_firmware
  • lenovo_ideapad_320-15abr_firmware
  • y720-15ikb
  • rescuer_y520-15ikbm
  • lenovo_ideapad_320s-15ikbr
  • lenovo_yoga_520-14ikb
  • lenovo_tianyi_310-15ikb_firmware
  • 520-15ikbrn_firmware
  • flex_5-1570
  • v330-14isk
  • nano110-14ikb
  • lenovo_ideapad_520s-14ikbr
  • yoga_310-11iap
  • lenovo_ideapad_720s-14ikb_firmware
  • lenovo_ideapad_flex_5-1470

lenovo

  • v310-14isk_firmware
  • e52-80_firmware
  • v310-15isk_firmware
  • v310-14ikb_firmware
  • v310-15ikb_firmware
  • v510-14ikb_firmware
  • e42-80_firmware
  • v510-15ikb_firmware
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')