CVE-2020-8332

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/10/2020
Last modified:
29/10/2020

Description

A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:bladecenter_hs23_firmware:*:*:*:*:*:*:*:* tke170b (excluding)
cpe:2.3:h:lenovo:bladecenter_hs23:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:bladecenter_hs23e_firmware:*:*:*:*:*:*:*:* ahe172b (excluding)
cpe:2.3:h:lenovo:bladecenter_hs23e:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:compute_node-x440_firmware:*:*:*:*:*:*:*:* cge128a (excluding)
cpe:2.3:h:lenovo:compute_node-x440:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:flex_system_x220_firmware:*:*:*:*:*:*:*:* kse170b (excluding)
cpe:2.3:h:lenovo:flex_system_x220:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:flex_system_x240_firmware:*:*:*:*:*:*:*:* b2e172b (excluding)
cpe:2.3:h:lenovo:flex_system_x240:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:flex_system_x440_firmware:*:*:*:*:*:*:*:* cne172b (excluding)
cpe:2.3:h:lenovo:flex_system_x440:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:nextscale_nx360_m4_firmware:*:*:*:*:*:*:*:* fhe132b (excluding)
cpe:2.3:h:lenovo:nextscale_nx360_m4:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:system_x3300_m4_firmware:*:*:*:*:*:*:*:* yae166b (excluding)


References to Advisories, Solutions, and Tools