Vulnerability Description
A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | 330-14Ast Firmware | - |
| Lenovo | 330-14Ast | - |
| Lenovo | 330-15Ast Firmware | - |
| Lenovo | 330-15Ast | - |
| Lenovo | 330-17Ast Firmware | - |
| Lenovo | 330-17Ast | - |
| Lenovo | 340C-15Api Firmware | - |
| Lenovo | 340C-15Api | - |
| Lenovo | 340C-15Ast Firmware | - |
| Lenovo | 340C-15Ast | - |
| Lenovo | 720S Touch-15Ikb Firmware | - |
| Lenovo | 720S Touch-15Ikb | - |
| Lenovo | 720S-15Ikb Firmware | - |
| Lenovo | 720S-15Ikb | - |
| Lenovo | 730S-13Iwl Firmware | - |
| Lenovo | 730S-13Iwl | - |
| Lenovo | C640-Iml Firmware | - |
| Lenovo | C640-Iml | - |
| Lenovo | E42-80 Firmware | - |
| Lenovo | E42-80 | - |
References
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
FAQ
What is CVE-2020-8322?
CVE-2020-8322 is a vulnerability with a CVSS score of 6.4 (MEDIUM). A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
How severe is CVE-2020-8322?
CVE-2020-8322 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8322?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo 330-14Ast Firmware, Lenovo 330-14Ast, Lenovo 330-15Ast Firmware, Lenovo 330-15Ast, Lenovo 330-17Ast Firmware.