A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Bladecenter Hs23
Subscribe
Bladecenter Hs23 Firmware
Subscribe
Bladecenter Hs23e
Subscribe
Bladecenter Hs23e Firmware
Subscribe
Compute Node-x440
Subscribe
Compute Node-x440 Firmware
Subscribe
Flex System X220
Subscribe
Flex System X220 Firmware
Subscribe
Flex System X240
Subscribe
Flex System X240 Firmware
Subscribe
Flex System X440
Subscribe
Flex System X440 Firmware
Subscribe
Idataplex Dx360 M4
Subscribe
Idataplex Dx360 M4 Firmware
Subscribe
Idataplex Dx360 M4 Water Cooled
Subscribe
Idataplex Dx360 M4 Water Cooled Firmware
Subscribe
Nextscale Nx360 M4
Subscribe
Nextscale Nx360 M4 Firmware
Subscribe
System X3300 M4
Subscribe
System X3300 M4 Firmware
Subscribe
System X3500 M4
Subscribe
System X3500 M4 Firmware
Subscribe
System X3530 M4
Subscribe
System X3530 M4 Firmware
Subscribe
System X3550 M4
Subscribe
System X3550 M4 Firmware
Subscribe
System X3630 M4
Subscribe
System X3630 M4 Firmware
Subscribe
System X3650 M4
Subscribe
System X3650 M4 Bd
Subscribe
System X3650 M4 Bd Firmware
Subscribe
System X3650 M4 Firmware
Subscribe
System X3650 M4 Hd
Subscribe
System X3650 M4 Hd Firmware
Subscribe
System X3750 M4
Subscribe
System X3750 M4 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-29199 | A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected. |
Fixes
Solution
Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-38625.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-38625 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-04T09:56:28.331Z
Reserved: 2020-01-28T00:00:00
Link: CVE-2020-8332
No data.
Status : Modified
Published: 2020-10-14T22:15:13.403
Modified: 2024-11-21T05:38:43.570
Link: CVE-2020-8332
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD