A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution
Published Oct 14, 2020
6.4
MEDIUMCVSS 3.1
EPSS 0.23%
Description
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
Affected products
-
Affected
- various
-
Affected
- various
Configuration 1
- < tke170b
Running on/with
- n/a
Configuration 2
- < ahe172b
Running on/with
- n/a
Configuration 3
- < cge128a
Running on/with
- n/a
Configuration 4
- < kse170b
Running on/with
- n/a
Configuration 5
- < b2e172b
Running on/with
- n/a
Configuration 6
- < cne172b
Running on/with
- n/a
Configuration 7
- < fhe132b
Running on/with
- n/a
Configuration 8
- < yae166b
Running on/with
- n/a
Configuration 9
- < y5e170b
Running on/with
- n/a
Configuration 10
- < bee174b
Running on/with
- n/a
Configuration 11
- < d7e174b
Running on/with
- n/a
Configuration 12
- < bee174b
Running on/with
- n/a
Configuration 13
- < vve172b
Running on/with
- n/a
Configuration 14
- < vve172b
Running on/with
- n/a
Configuration 15
- < vve172b
Running on/with
- n/a
Configuration 16
- < a5e130a
Running on/with
- n/a
Configuration 17
- < koe170b
Running on/with
- n/a
Configuration 18
- < tde168b
Running on/with
- n/a
Configuration 19
- < tde168b
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update system firmware to the version (or newer) indicated for your model in the Product Impact section in LEN-38625.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29199 Advisory
- https://support.lenovo.com/us/en/product_security/LEN-38625 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29199 | Advisory | |
| https://support.lenovo.com/us/en/product_security/LEN-38625 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data