CVE-2020-8332
6.4
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.5 / Impact: 5.9
Source: NVD
Description
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
Affected (19)
Products: Lenovo: Bladecenter Hs23 Firmware, Bladecenter Hs23e Firmware, Compute Node X440 Firmware, Flex System X220 Firmware, Flex System X240 Firmware, Flex System X440 Firmware, Nextscale Nx360 M4 Firmware, System X3300 M4 Firmware, System X3500 M4 Firmware, System X3530 M4 Firmware, System X3550 M4 Firmware, System X3630 M4 Firmware, System X3650 M4 Firmware, System X3650 M4 Bd Firmware, System X3650 M4 Hd Firmware, System X3750 M4 Firmware, Idataplex Dx360 M4 Firmware, Idataplex Dx360 M4 Water Cooled Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before tke170b |
| Running on/with | Platform Versions |
|---|---|
Lenovo Bladecenter Hs23 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before ahe172b |
| Running on/with | Platform Versions |
|---|---|
Lenovo Bladecenter Hs23e | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before cge128a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Compute Node X440 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before kse170b |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex System X220 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before b2e172b |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex System X240 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before cne172b |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex System X440 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before fhe132b |
| Running on/with | Platform Versions |
|---|---|
Lenovo Nextscale Nx360 M4 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before yae166b |
| Running on/with | Platform Versions |
|---|---|
Lenovo System X3300 M4 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before y5e170b |
| Running on/with | Platform Versions |
|---|---|
Lenovo System X3500 M4 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before bee174b |
| Running on/with | Platform Versions |
|---|---|
Lenovo System X3530 M4 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before d7e174b |
| Running on/with | Platform Versions |
|---|---|
Lenovo System X3550 M4 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before bee174b |
| Running on/with | Platform Versions |
|---|---|
Lenovo System X3630 M4 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before vve172b |
| Running on/with | Platform Versions |
|---|---|
Lenovo System X3650 M4 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before vve172b |
| Running on/with | Platform Versions |
|---|---|
Lenovo System X3650 M4 Bd | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before vve172b |
| Running on/with | Platform Versions |
|---|---|
Lenovo System X3650 M4 Hd | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before a5e130a |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before koe170b |
| Running on/with | Platform Versions |
|---|---|
Lenovo System X3750 M4 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before tde168b |
| Running on/with | Platform Versions |
|---|---|
Lenovo Idataplex Dx360 M4 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before tde168b |
| Running on/with | Platform Versions |
|---|---|
Lenovo Idataplex Dx360 M4 Water Cooled | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.