Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Flex System X240 M5
Subscribe
Flex System X240 M5 Bios
Subscribe
Flex System X280 X6
Subscribe
Flex System X280 X6 Bios
Subscribe
Flex System X480 X6
Subscribe
Flex System X480 X6 Bios
Subscribe
Flex System X880
Subscribe
Flex System X880 Bios
Subscribe
Nextscale Nx360 M5
Subscribe
Nextscale Nx360 M5 Bios
Subscribe
System X3250 M6
Subscribe
System X3250 M6 Bios
Subscribe
System X3500 M5
Subscribe
System X3500 M5 Bios
Subscribe
System X3550 M5
Subscribe
System X3550 M5 Bios
Subscribe
System X3650 M5
Subscribe
System X3650 M5 Bios
Subscribe
System X3850 X6
Subscribe
System X3850 X6 Bios
Subscribe
System X3950 X6
Subscribe
System X3950 X6 Bios
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-12892 | Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/solutions/LEN-20241 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-16T23:56:19.792Z
Reserved: 2016-12-16T00:00:00
Link: CVE-2017-3775
No data.
Status : Modified
Published: 2018-05-04T17:29:00.223
Modified: 2024-11-21T03:26:06.720
Link: CVE-2017-3775
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD