CVE-2020-8333
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
Affected (27)
Products: Lenovo: 63 Firmware, H50 30g Firmware, M4500 Firmware, M4550 Firmware, Qitian 4500 Firmware, Qitian B4550 Firmware, Qitian M4550 Firmware, Thinkcentre E73 Firmware, Thinkcentre E73s Firmware, Thinkcentre E93 Firmware, Thinkcentre M4500k Firmware, Thinkcentre M4500q Firmware, Thinkcentre M4500t Firmware, Thinkcentre M4500s Firmware, Yangtian Afh81 Firmware, Yangtian Mc H81 Firmware, Yangtian Mf H81 Pci Firmware, Yangtian Wf H81 Pci Firmware, Yangtian Tc H81 Pci Firmware, Yangtian Wcc H81 Pci Firmware, Thinkcentre M9350z Firmware, Thinkcentre M93z Firmware, Thinkstation C30 Firmware, Thinkstation D30 Firmware, Thinkstation E32 Firmware, Thinkstation P300 Firmware, Thinkstation S30 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo 63 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo H50 30g | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo M4500 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo M4550 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Qitian 4500 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Qitian B4550 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Qitian M4550 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre E73 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre E73s | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before fbktdea |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre E93 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M4500k | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before fhkt85a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M4500q | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M4500t | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M4500s | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yangtian Afh81 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yangtian Mc H81 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yangtian Mf H81 Pci | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yangtian Wf H81 Pci | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yangtian Tc H81 Pci | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before fckt98a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Yangtian Wcc H81 Pci | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before fekta2a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M9350z | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before fekta2a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkcentre M93z | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before a3kt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation C30 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before a3kt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation D30 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before fbktdea |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation E32 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before a2kt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation P300 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before a2kt70a |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkstation S30 | All versions |
References (2)
Source: psirt@lenovo.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.