Target Platform
CHIPSET DB
Firmware Modifications
HAP / AltMeDisable Bit
Run `me_cleaner -S` on flash descriptor
Coreboot / Libreboot Flashed
Replace proprietary Lenovo UEFI payload
Hardware Programmer Attached
CH341A external SOIC-8 clip verified
Silicon Architecture & Execution Pipeline
DUAL FLASH SOIC-8 (8MB + 4MB)
Flash Accessibility
SOIC-8 Clip (Winbond)
Standard 8-pin probe clips directly onto the physical PCB chip.
Management Engine State
Disabled via HAP bit
Ring -3 execution halted post-HW initialization via `me_cleaner -S`.
Boot Guard Status
No Fused Keys
Silicon accepts user-compiled Coreboot/SeaBIOS without cryptographic rejection.
Network Backdoor Risk
Zero Network Access
Out-of-band Intel AMT network stack unprovisioned and disabled.
[0.000000] ThinkPad Security Audit Engine v2.4 initialized. Target: X230
[0.001200] ME Descriptor: AltMeDisable / HAP flag set to TRUE. ME Ring-3 ROM halted.
[0.002100] BIOS AMT: Permanently Disabled flag burned into NVRAM.
[0.003400] Firmware Payload: Coreboot open-source ROM loaded. Lenovo proprietary binaries evicted.
[0.004900] CVE-2019-0090: Immune (Ivy Bridge pre-dates vulnerable Skylake CSME mask ROM).