Vulnerability Description
A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | 63 Firmware | < fckt98a |
| Lenovo | 63 | - |
| Lenovo | H50-30G Firmware | < fckt98a |
| Lenovo | H50-30G | - |
| Lenovo | M4500 Firmware | < fckt98a |
| Lenovo | M4500 | - |
| Lenovo | M4550 Firmware | < fckt98a |
| Lenovo | M4550 | - |
| Lenovo | Qitian 4500 Firmware | < fckt98a |
| Lenovo | Qitian 4500 | - |
| Lenovo | Qitian B4550 Firmware | < fckt98a |
| Lenovo | Qitian B4550 | - |
| Lenovo | Qitian M4550 Firmware | < fckt98a |
| Lenovo | Qitian M4550 | - |
| Lenovo | Thinkcentre E73 Firmware | < fckt98a |
| Lenovo | Thinkcentre E73 | - |
| Lenovo | Thinkcentre E73S Firmware | < fckt98a |
| Lenovo | Thinkcentre E73S | - |
| Lenovo | Thinkcentre E93 Firmware | < fbktdea |
| Lenovo | Thinkcentre E93 | - |
References
- https://support.lenovo.com/us/en/product_security/LEN-30042PatchVendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-30042PatchVendor Advisory
FAQ
What is CVE-2020-8333?
CVE-2020-8333 is a vulnerability with a CVSS score of 6.4 (MEDIUM). A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
How severe is CVE-2020-8333?
CVE-2020-8333 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8333?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo 63 Firmware, Lenovo 63, Lenovo H50-30G Firmware, Lenovo H50-30G, Lenovo M4500 Firmware.