Description
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
Published: 2020-10-14
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-38625.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-29199 A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
History

No history.

Subscriptions

Lenovo Bladecenter Hs23 Bladecenter Hs23 Firmware Bladecenter Hs23e Bladecenter Hs23e Firmware Compute Node-x440 Compute Node-x440 Firmware Flex System X220 Flex System X220 Firmware Flex System X240 Flex System X240 Firmware Flex System X440 Flex System X440 Firmware Idataplex Dx360 M4 Idataplex Dx360 M4 Firmware Idataplex Dx360 M4 Water Cooled Idataplex Dx360 M4 Water Cooled Firmware Nextscale Nx360 M4 Nextscale Nx360 M4 Firmware System X3300 M4 System X3300 M4 Firmware System X3500 M4 System X3500 M4 Firmware System X3530 M4 System X3530 M4 Firmware System X3550 M4 System X3550 M4 Firmware System X3630 M4 System X3630 M4 Firmware System X3650 M4 System X3650 M4 Bd System X3650 M4 Bd Firmware System X3650 M4 Firmware System X3650 M4 Hd System X3650 M4 Hd Firmware System X3750 M4 System X3750 M4 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-04T09:56:28.331Z

Reserved: 2020-01-28T00:00:00.000Z

Link: CVE-2020-8332

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-14T22:15:13.403

Modified: 2024-11-21T05:38:43.570

Link: CVE-2020-8332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses