Thinkpad X1 Carbon \(20bx\) Firmware
2 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Thinkpad X1 Carbon \(20bx\) Firmware, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
Thinkpad X1 Carbon \(20bx\) Firmware CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 2 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Medium2
Latest CVEs
The 2 most recently published vulnerabilities affecting Thinkpad X1 Carbon \(20bx\) Firmware.
- CVE-2020-8335The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS ...6.1
- CVE-2020-8323A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.6.4
Product grouping is registry-driven, with AI assist and human review. How it works