Description
A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
Published: 2020-09-24
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-30042.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-29200 A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
History

No history.

Subscriptions

Lenovo 63 63 Firmware H50-30g H50-30g Firmware M4500 M4500 Firmware M4550 M4550 Firmware Qitian 4500 Qitian 4500 Firmware Qitian B4550 Qitian B4550 Firmware Qitian M4550 Qitian M4550 Firmware Thinkcentre E73 Thinkcentre E73 Firmware Thinkcentre E73s Thinkcentre E73s Firmware Thinkcentre E93 Thinkcentre E93 Firmware Thinkcentre M4500k Thinkcentre M4500k Firmware Thinkcentre M4500q Thinkcentre M4500q Firmware Thinkcentre M4500s Thinkcentre M4500s Firmware Thinkcentre M4500t Thinkcentre M4500t Firmware Thinkcentre M9350z Thinkcentre M9350z Firmware Thinkcentre M93z Thinkcentre M93z Firmware Thinkstation C30 Thinkstation C30 Firmware Thinkstation D30 Thinkstation D30 Firmware Thinkstation E32 Thinkstation E32 Firmware Thinkstation P300 Thinkstation P300 Firmware Thinkstation S30 Thinkstation S30 Firmware Yangtian Afh81 Yangtian Afh81 Firmware Yangtian Mc H81 Yangtian Mc H81 Firmware Yangtian Mf H81 Pci Yangtian Mf H81 Pci Firmware Yangtian Tc H81 Pci Yangtian Tc H81 Pci Firmware Yangtian Wcc H81 Pci Yangtian Wcc H81 Pci Firmware Yangtian Wf H81 Pci Yangtian Wf H81 Pci Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-16T17:38:49.850Z

Reserved: 2020-01-28T00:00:00.000Z

Link: CVE-2020-8333

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-24T21:15:15.873

Modified: 2024-11-21T05:38:43.713

Link: CVE-2020-8333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses