Description
A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Published: 2022-04-22
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-77639.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-34069 A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
History

No history.

Subscriptions

Lenovo A340-22icb A340-22icb Firmware A340-22ick A340-22ick Firmware A340-24icb A340-24icb Firmware A340-24ick A340-24ick Firmware A540-24icb A540-24icb Firmware A540-27icb A540-27icb Firmware Ideacentre 5-14iob6 Ideacentre 5-14iob6 Firmware Ideacentre 510s-07icb Ideacentre 510s-07icb Firmware Ideacentre 510s-07ick Ideacentre 510s-07ick Firmware Ideacentre Aio 3-22ada6 Ideacentre Aio 3-22ada6 Firmware Ideacentre Aio 3-22iil5 Ideacentre Aio 3-22iil5 Firmware Ideacentre Aio 3-22itl6 Ideacentre Aio 3-22itl6 Firmware Ideacentre Aio 3-24ada6 Ideacentre Aio 3-24ada6 Firmware Ideacentre Aio 3-24iil5 Ideacentre Aio 3-24iil5 Firmware Ideacentre Aio 3-24itl6 Ideacentre Aio 3-24itl6 Firmware Ideacentre Aio 3-27itl6 Ideacentre Aio 3-27itl6 Firmware Ideacentre Creator 5-14iob6 Ideacentre Creator 5-14iob6 Firmware Ideacentre Gaming 5-14iob6 Ideacentre Gaming 5-14iob6 Firmware Se30 Se30 Firmware Thinkcentre M600 Thinkcentre M600 Firmware Thinkcentre M700 Tiny Thinkcentre M700 Tiny Firmware Thinkcentre M70a Thinkcentre M70a Firmware Thinkcentre M710e Thinkcentre M710e Firmware Thinkcentre M710q Thinkcentre M710q \(10yc\) Thinkcentre M710q \(10yc\) Firmware Thinkcentre M710q Firmware Thinkcentre M710s Thinkcentre M710s Firmware Thinkcentre M710t Thinkcentre M710t Firmware Thinkcentre M720e Thinkcentre M720e Firmware Thinkcentre M75n Thinkcentre M75n Firmware Thinkcentre M800 Thinkcentre M800 Firmware Thinkcentre M810z Thinkcentre M810z Firmware Thinkcentre M820z Thinkcentre M820z Firmware Thinkcentre M900 Thinkcentre M900 Firmware Thinkcentre M900x Thinkcentre M900x Firmware Thinkcentre M90a \(gen 2\) Thinkcentre M90a \(gen 2\) Firmware Thinkcentre M910q Thinkcentre M910q Firmware Thinkcentre M910s Thinkcentre M910s Firmware Thinkcentre M910t Thinkcentre M910t Firmware Thinkcentre M910x Thinkcentre M910x Firmware Thinkstation P310 Thinkstation P310 Firmware Thinkstation P320 Thinkstation P320 Firmware Thinkstation P320 Tiny Thinkstation P320 Tiny Firmware V30a-22iml V30a-22iml Firmware V30a-24iml V30a-24iml Firmware V410z V410z Firmware V50t-13iob G2 V50t-13iob G2 Firmware V520 V520 Firmware V520s V520s Firmware V530-15icb V530-15icb Firmware V530-15icr V530-15icr Firmware V530s-07icb V530s-07icb Firmware V530s-07icr V530s-07icr Firmware V540-24iwl V540-24iwl Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:16:04.358Z

Reserved: 2022-01-24T00:00:00.000Z

Link: CVE-2021-4211

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-22T21:15:10.007

Modified: 2024-11-21T06:37:09.520

Link: CVE-2021-4211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses