MEDIUM
A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code
Published Sep 13, 2024
6.7
MEDIUMCVSS 3.1
EPSS 0.21%
Description
A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code.
Affected products
-
- Version 0StatusaffectedConstraints<=S0EKT43A
- Version
-
- Version 0StatusaffectedConstraints<ITE134A
- Version
-
- Version 0StatusaffectedConstraints<TOE112D
- Version
-
- Version 0StatusaffectedConstraints<ITE134A
- Version
-
- Version 0StatusaffectedConstraints<TOE112D
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Lenovo | P360 Workstation (ThinkStation) BIOS | unaffected |
| ||||||
| Lenovo | ST50 (ThinkSystem) BIOS | unaffected |
| ||||||
| Lenovo | ST50 V2 (ThinkSystem) BIOS | unaffected |
| ||||||
| Lenovo | ST58 (ThinkSystem) BIOS | unaffected |
| ||||||
| Lenovo | ST58 V2 (ThinkSystem) BIOS | unaffected |
|
No data.
-
- Version 0StatusaffectedConstraints<s0ekt43a
- Version
-
- Version 0StatusaffectedConstraints<ite134a
- Version
-
- Version 0StatusaffectedConstraints<toe112d
- Version
-
- Version 0StatusaffectedConstraints<ite134a
- Version
-
- Version 0StatusaffectedConstraints<toe112d
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Lenovo | Thinkstation P360 Workstation Firmware | unaffected |
| ||||||
| Lenovo | Thinksystem St50 Firmware | unaffected |
| ||||||
| Lenovo | Thinksystem St50 V2 Firmware | unaffected |
| ||||||
| Lenovo | Thinksystem St58 Firmware | unaffected |
| ||||||
| Lenovo | Thinksystem St58 V2 Firmware | unaffected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update system firmware to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-165524
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner lenovo
Published Sep 13, 2024
Updated Sep 16, 2024
Reserved May 6, 2024
Link CVE-2024-4550
CISA Vulnrichment
Updated Sep 13, 2024
ENISA EUVD
EUVD-2024-44162 Assigner lenovo
Published Sep 13, 2024
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2024-44162