A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution

Project Subscriptions

Vendors Products
63 Firmware Subscribe
H50-30g Subscribe
H50-30g Firmware Subscribe
M4500 Firmware Subscribe
M4550 Firmware Subscribe
Qitian 4500 Subscribe
Qitian 4500 Firmware Subscribe
Qitian B4550 Subscribe
Qitian B4550 Firmware Subscribe
Qitian M4550 Subscribe
Qitian M4550 Firmware Subscribe
Thinkcentre E73 Subscribe
Thinkcentre E73 Firmware Subscribe
Thinkcentre E73s Subscribe
Thinkcentre E73s Firmware Subscribe
Thinkcentre E93 Subscribe
Thinkcentre E93 Firmware Subscribe
Thinkcentre M4500k Subscribe
Thinkcentre M4500k Firmware Subscribe
Thinkcentre M4500q Subscribe
Thinkcentre M4500q Firmware Subscribe
Thinkcentre M4500s Subscribe
Thinkcentre M4500s Firmware Subscribe
Thinkcentre M4500t Subscribe
Thinkcentre M4500t Firmware Subscribe
Thinkcentre M9350z Subscribe
Thinkcentre M9350z Firmware Subscribe
Thinkcentre M93z Subscribe
Thinkcentre M93z Firmware Subscribe
Thinkstation C30 Subscribe
Thinkstation C30 Firmware Subscribe
Thinkstation D30 Subscribe
Thinkstation D30 Firmware Subscribe
Thinkstation E32 Subscribe
Thinkstation E32 Firmware Subscribe
Thinkstation P300 Subscribe
Thinkstation P300 Firmware Subscribe
Thinkstation S30 Subscribe
Thinkstation S30 Firmware Subscribe
Yangtian Afh81 Subscribe
Yangtian Afh81 Firmware Subscribe
Yangtian Mc H81 Subscribe
Yangtian Mc H81 Firmware Subscribe
Yangtian Mf H81 Pci Subscribe
Yangtian Mf H81 Pci Firmware Subscribe
Yangtian Tc H81 Pci Subscribe
Yangtian Tc H81 Pci Firmware Subscribe
Yangtian Wcc H81 Pci Subscribe
Yangtian Wcc H81 Pci Firmware Subscribe
Yangtian Wf H81 Pci Subscribe
Yangtian Wf H81 Pci Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-29200 A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-30042.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-16T17:38:49.850Z

Reserved: 2020-01-28T00:00:00

Link: CVE-2020-8333

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-24T21:15:15.873

Modified: 2024-11-21T05:38:43.713

Link: CVE-2020-8333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses