Take a look at our
ThinkPads.com HOME PAGE
For those who might want to contribute to the blog, start here: Editors Alley Topic
Then contact Bill with a Private Message

Intel-SA-00086 Detection Tool - T420 still vulnerable

T400/410/420 and T500/510/520 series specific matters only
Post Reply
Message
Author
skx
Freshman Member
Posts: 55
Joined: Mon Jul 09, 2018 6:25 pm
Location: Belgium

Intel-SA-00086 Detection Tool - T420 still vulnerable

#1 Post by skx » Wed Aug 29, 2018 6:54 am

INTEL-SA-00086 Detection Tool
Copyright(C) 2017-2018, Intel Corporation, All rights reserved.

Application Version: 1.2.7.0
Scan date: 2018-08-29 11:51:55 GMT

*** Host Computer Information ***
Name: T420
Manufacturer: LENOVO
Processor Name: Intel(R) Core(TM) i5-2520M CPU @ 2.50GHz
OS Version: debian 9.5 (4.9.0-8-amd64)

*** Intel(R) ME Information ***
Engine: Intel(R) Management Engine
Version: 7.1.91.3272
SVN: 0

*** Risk Assessment ***
Based on the analysis performed by this tool: This system is vulnerable.
Explanation:
The detected version of the Intel(R) Management Engine firmware is considered vulnerable for INTEL-SA-00086.
Contact your system manufacturer for support and remediation of this system.

For more information refer to the INTEL-SA-00086 Detection Tool Guide or the Intel Security Advisory Intel-SA-00086 at the following link:
https://www.intel.com/sa-00086-support
https://pcsupport.lenovo.com/us/nl/prod ... /downloads
https://downloadcenter.intel.com/downlo ... ction-Tool

Hi all, can people confirm that after updating latest firmware for T420, the Intel ME remains vulnerable?
ThinkPad X220: i5-2520M CPU 2.5GHz - 8GB RAM 1333 MHz - SSD 860 EVO 250GB - Debian Stretch
ThinkPad X230: i5-3320M CPU 3.3GHz - 8GB RAM 1600 MHz - SSD 860 EVO 500GB - Debian Stretch

skx
Freshman Member
Posts: 55
Joined: Mon Jul 09, 2018 6:25 pm
Location: Belgium

Re: Intel-SA-00086 Detection Tool - T420 still vulnerable

#2 Post by skx » Wed Aug 29, 2018 6:34 pm

Hmm... nobody care about this? Same applies for X220 and probably many more laptops. Is the *20 series still supported by Lenovo? These second Intel ME vulnerabilities are patched for x230 by Lenovo.
ThinkPad X220: i5-2520M CPU 2.5GHz - 8GB RAM 1333 MHz - SSD 860 EVO 250GB - Debian Stretch
ThinkPad X230: i5-3320M CPU 3.3GHz - 8GB RAM 1600 MHz - SSD 860 EVO 500GB - Debian Stretch

TonyJZX
Senior Member
Senior Member
Posts: 547
Joined: Sun Feb 19, 2006 12:33 am

Re: Intel-SA-00086 Detection Tool - T420 still vulnerable

#3 Post by TonyJZX » Wed Aug 29, 2018 7:39 pm

I think people are complacent about these things as "they dont affect me".

I have a 420s without the spectre meltdown fixes but a 420 with them - seems to be no performance difference and I'm surprised these are even officially supported.

I think same gen. HP is still supported but Dells are not.

Dell 3rd gen is.

shawross
Junior Member
Junior Member
Posts: 482
Joined: Mon Oct 28, 2013 5:48 am
Location: Perth Aus / Thailand

Re: Intel-SA-00086 Detection Tool - T420 still vulnerable

#4 Post by shawross » Thu Aug 30, 2018 4:39 am

skx wrote:Hmm... nobody care about this?
I care and I am sure the majority of forum members do. I ran the Intel "Discovery Tool" and got the following.

Tool Started 30/08/2018 5:20:25 PM
Name: X220-PC
Manufacturer: LENOVO
Model: 4291HL3
Processor Name: Intel(R) Core(TM) i5-2520M CPU @ 2.50GHz
OS Version: Microsoft Windows 7 Ultimate
Engine: Intel(R) Management Engine
Version: 7.1.91.3272
SVN: 0
Status: This system is not vulnerable.
Tool Stopped
Active --- Love the X series
X301 SU9400 IDA Mod - W 7 / X201 540M - W 7 / X220 2520 - W7

Nostalgia
X61 T7500 / T41 T42 T43 / A31

Rogue daily driver - Samsung RV511 15.6 " Screen - W 7

skx
Freshman Member
Posts: 55
Joined: Mon Jul 09, 2018 6:25 pm
Location: Belgium

Re: Intel-SA-00086 Detection Tool - T420 still vulnerable

#5 Post by skx » Thu Aug 30, 2018 4:57 am

shawross wrote:
Thu Aug 30, 2018 4:39 am
skx wrote:Hmm... nobody care about this?
I care and I am sure the majority of forum members do. I ran the Intel "Discovery Tool" and got the following.

Tool Started 30/08/2018 5:20:25 PM
Name: X220-PC
Manufacturer: LENOVO
Model: 4291HL3
Processor Name: Intel(R) Core(TM) i5-2520M CPU @ 2.50GHz
OS Version: Microsoft Windows 7 Ultimate
Engine: Intel(R) Management Engine
Version: 7.1.91.3272
SVN: 0
Status: This system is not vulnerable.
Tool Stopped
Interesting, did you run the detection tool on Linux or Windows? Seems like the Linux tool is falsely reporting vulnerable.

Could someone verify Intel's detection python script tool on a Linux distro of choice with latest ME firmware 7.1.91.3272 and report back? Windows user can verify it as well by using a live distro and executing 'sudo python intel_sa00086.py'
ThinkPad X220: i5-2520M CPU 2.5GHz - 8GB RAM 1333 MHz - SSD 860 EVO 250GB - Debian Stretch
ThinkPad X230: i5-3320M CPU 3.3GHz - 8GB RAM 1600 MHz - SSD 860 EVO 500GB - Debian Stretch

shawross
Junior Member
Junior Member
Posts: 482
Joined: Mon Oct 28, 2013 5:48 am
Location: Perth Aus / Thailand

Re: Intel-SA-00086 Detection Tool - T420 still vulnerable

#6 Post by shawross » Thu Aug 30, 2018 5:13 am

Yes I am running Windows 7 as the majority do on this forum I think.

But there should be some linux users who can check for you.
Active --- Love the X series
X301 SU9400 IDA Mod - W 7 / X201 540M - W 7 / X220 2520 - W7

Nostalgia
X61 T7500 / T41 T42 T43 / A31

Rogue daily driver - Samsung RV511 15.6 " Screen - W 7

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “ThinkPad T400/410/420 and T500/510/520 Series”

Who is online

Users browsing this forum: GrifterGuru and 8 guests