Metrics
Affected Vendors & Products
No advisories yet.
Solution
Update to the version (or newer) indicated for your model in the Product Impact section of the advisory: https://support.lenovo.com/us/en/product_security/LEN-213040
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-213040 |
|
Wed, 11 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modify data and execute arbitrary code. | |
| First Time appeared |
Lenovo
Lenovo thinkpad P14s Gen 5 Bios Lenovo thinkpad P15v Gen 3 Bios Lenovo thinkpad P16v Gen 1 Bios Lenovo thinkpad T14 Gen 5 Bios Lenovo thinkpad Z13 Gen 1 Bios Lenovo thinkpad Z13 Gen 2 Bios Lenovo thinkpad Z16 Gen 1 Bios Lenovo thinkpad Z16 Gen 2 Bios |
|
| Weaknesses | CWE-665 | |
| CPEs | cpe:2.3:a:lenovo:thinkpad_p14s_gen_5_bios:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:thinkpad_p15v_gen_3_bios:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:thinkpad_p16v_gen_1_bios:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:thinkpad_t14_gen_5_bios:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:thinkpad_z13_gen_1_bios:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:thinkpad_z13_gen_2_bios:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:thinkpad_z16_gen_1_bios:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:thinkpad_z16_gen_2_bios:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Lenovo
Lenovo thinkpad P14s Gen 5 Bios Lenovo thinkpad P15v Gen 3 Bios Lenovo thinkpad P16v Gen 1 Bios Lenovo thinkpad T14 Gen 5 Bios Lenovo thinkpad Z13 Gen 1 Bios Lenovo thinkpad Z13 Gen 2 Bios Lenovo thinkpad Z16 Gen 1 Bios Lenovo thinkpad Z16 Gen 2 Bios |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-03-11T20:21:17.160Z
Reserved: 2026-01-14T14:41:45.333Z
Link: CVE-2026-0940
No data.
Status : Received
Published: 2026-03-11T21:16:13.887
Modified: 2026-03-11T21:16:13.887
Link: CVE-2026-0940
No data.
OpenCVE Enrichment
No data.