A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Project Subscriptions

Vendors Products
A540-24icb Subscribe
A540-24icb Firmware Subscribe
A540-27icb Subscribe
A540-27icb Firmware Subscribe
Ideacentre 5-14imb05 Subscribe
Ideacentre 5-14imb05 Firmware Subscribe
Ideacentre Aio 3-22ada6 Subscribe
Ideacentre Aio 3-22ada6 Firmware Subscribe
Ideacentre Aio 3-22iil5 Subscribe
Ideacentre Aio 3-22iil5 Firmware Subscribe
Ideacentre Aio 3-22itl6 Subscribe
Ideacentre Aio 3-22itl6 Firmware Subscribe
Ideacentre Aio 3-24ada6 Subscribe
Ideacentre Aio 3-24ada6 Firmware Subscribe
Ideacentre Aio 3-24iil5 Subscribe
Ideacentre Aio 3-24iil5 Firmware Subscribe
Ideacentre Aio 3-24itl6 Subscribe
Ideacentre Aio 3-24itl6 Firmware Subscribe
Ideacentre Aio 3-27itl6 Subscribe
Ideacentre Aio 3-27itl6 Firmware Subscribe
Ideacentre C5-14imb05 Subscribe
Ideacentre C5-14imb05 Firmware Subscribe
Ideacentre G5-14imb05 Subscribe
Ideacentre G5-14imb05 Firmware Subscribe
Stadia Ggp-120 Subscribe
Stadia Ggp-120 Firmware Subscribe
Thinkcentre M700 Subscribe
Thinkcentre M700 Firmware Subscribe
Thinkcentre M700 Tiny Subscribe
Thinkcentre M700 Tiny Firmware Subscribe
Thinkcentre M70a Subscribe
Thinkcentre M70a Firmware Subscribe
Thinkcentre M75n Subscribe
Thinkcentre M75n Firmware Subscribe
Thinkcentre M800 Subscribe
Thinkcentre M800 Firmware Subscribe
Thinkcentre M810z Subscribe
Thinkcentre M810z Firmware Subscribe
Thinkcentre M820z Subscribe
Thinkcentre M820z Firmware Subscribe
Thinkcentre M900 Subscribe
Thinkcentre M900 Firmware Subscribe
Thinkcentre M900x Subscribe
Thinkcentre M900x Firmware Subscribe
Thinkcentre M90a Gen2 Subscribe
Thinkcentre M90a Gen2 Firmware Subscribe
Thinkcentre M910z Subscribe
Thinkcentre M910z Firmware Subscribe
Thinkcentre X1 Subscribe
Thinkcentre X1 Firmware Subscribe
Thinkedge Se30 Subscribe
Thinkedge Se30 Firmware Subscribe
Thinkstation P310 Subscribe
Thinkstation P310 Firmware Subscribe
Thinkstation P520 Subscribe
Thinkstation P520 Firmware Subscribe
Thinkstation P520c Subscribe
Thinkstation P520c Firmware Subscribe
V410z Firmware Subscribe
V50t-13imb Subscribe
V50t-13imb Firmware Subscribe
V540-24iwl Subscribe
V540-24iwl Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-34068 A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Fixes

Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-77639.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:16:04.261Z

Reserved: 2022-01-24T00:00:00

Link: CVE-2021-4210

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-22T21:15:09.950

Modified: 2024-11-21T06:37:09.330

Link: CVE-2021-4210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses