Description
A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Published: 2022-04-22
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-77639.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-34068 A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
History

No history.

Subscriptions

Lenovo A540-24icb A540-24icb Firmware A540-27icb A540-27icb Firmware Ideacentre 5-14imb05 Ideacentre 5-14imb05 Firmware Ideacentre Aio 3-22ada6 Ideacentre Aio 3-22ada6 Firmware Ideacentre Aio 3-22iil5 Ideacentre Aio 3-22iil5 Firmware Ideacentre Aio 3-22itl6 Ideacentre Aio 3-22itl6 Firmware Ideacentre Aio 3-24ada6 Ideacentre Aio 3-24ada6 Firmware Ideacentre Aio 3-24iil5 Ideacentre Aio 3-24iil5 Firmware Ideacentre Aio 3-24itl6 Ideacentre Aio 3-24itl6 Firmware Ideacentre Aio 3-27itl6 Ideacentre Aio 3-27itl6 Firmware Ideacentre C5-14imb05 Ideacentre C5-14imb05 Firmware Ideacentre G5-14imb05 Ideacentre G5-14imb05 Firmware Stadia Ggp-120 Stadia Ggp-120 Firmware Thinkcentre M700 Thinkcentre M700 Firmware Thinkcentre M700 Tiny Thinkcentre M700 Tiny Firmware Thinkcentre M70a Thinkcentre M70a Firmware Thinkcentre M75n Thinkcentre M75n Firmware Thinkcentre M800 Thinkcentre M800 Firmware Thinkcentre M810z Thinkcentre M810z Firmware Thinkcentre M820z Thinkcentre M820z Firmware Thinkcentre M900 Thinkcentre M900 Firmware Thinkcentre M900x Thinkcentre M900x Firmware Thinkcentre M90a Gen2 Thinkcentre M90a Gen2 Firmware Thinkcentre M910z Thinkcentre M910z Firmware Thinkcentre X1 Thinkcentre X1 Firmware Thinkedge Se30 Thinkedge Se30 Firmware Thinkstation P310 Thinkstation P310 Firmware Thinkstation P520 Thinkstation P520 Firmware Thinkstation P520c Thinkstation P520c Firmware V410z V410z Firmware V50t-13imb V50t-13imb Firmware V540-24iwl V540-24iwl Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:16:04.261Z

Reserved: 2022-01-24T00:00:00.000Z

Link: CVE-2021-4210

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-22T21:15:09.950

Modified: 2024-11-21T06:37:09.330

Link: CVE-2021-4210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses