MEDIUM · 6.4

CVE-2020-8332

A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in ...

Vulnerability Description

A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.

CVSS Score

6.4

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoBladecenter Hs23 Firmware< tke170b
LenovoBladecenter Hs23-
LenovoBladecenter Hs23E Firmware< ahe172b
LenovoBladecenter Hs23E-
LenovoCompute Node-X440 Firmware< cge128a
LenovoCompute Node-X440-
LenovoFlex System X220 Firmware< kse170b
LenovoFlex System X220-
LenovoFlex System X240 Firmware< b2e172b
LenovoFlex System X240-
LenovoFlex System X440 Firmware< cne172b
LenovoFlex System X440-
LenovoNextscale Nx360 M4 Firmware< fhe132b
LenovoNextscale Nx360 M4-
LenovoSystem X3300 M4 Firmware< yae166b
LenovoSystem X3300 M4-
LenovoSystem X3500 M4 Firmware< y5e170b
LenovoSystem X3500 M4-
LenovoSystem X3530 M4 Firmware< bee174b
LenovoSystem X3530 M4-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-8332?

CVE-2020-8332 is a vulnerability with a CVSS score of 6.4 (MEDIUM). A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in ...

How severe is CVE-2020-8332?

CVE-2020-8332 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8332?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Bladecenter Hs23 Firmware, Lenovo Bladecenter Hs23, Lenovo Bladecenter Hs23E Firmware, Lenovo Bladecenter Hs23E, Lenovo Compute Node-X440 Firmware.