7.2
CVE-2017-3753
- EPSS 0.05%
- Published 10.08.2017 00:29:00
- Last modified 20.04.2025 01:37:25
- Source psirt@lenovo.com
- Teams watchlist Login
- Open Login
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.
Data is provided by the National Vulnerability Database (NVD)
Lenovo ≫ Ideacentre 300-20ish Firmware Version-
Lenovo ≫ Ideacentre 300s-11ish Firmware Version-
Lenovo ≫ Ideacentre 510s-08ish Firmware Version-
Lenovo ≫ Ideacentre 700 Firmware Version-
Lenovo ≫ 63 Firmware Versionfckt78a
Lenovo ≫ H50-30g Firmware Versionfckt78a
Lenovo ≫ M4500 Firmware Versionfckt78a
Lenovo ≫ M4500 Id Firmware Versionfckt78a
Lenovo ≫ M4550 Id Firmware Versionfckt78a
Lenovo ≫ S500 Firmware Versionm0kkt24a
Lenovo ≫ V320-15iap Firmware Version-
Lenovo ≫ Thinkcentre E73 Firmware Versionfckt78a
Lenovo ≫ Thinkcentre E73s Firmware Versionfckt78a
Lenovo ≫ Thinkcentre E74 Firmware Versionm05kt54a
Lenovo ≫ Thinkcentre E74s Firmware Versionm05kt54a
Lenovo ≫ Thinkcentre E79 Firmware Versionm0lkt12a
Lenovo ≫ Thinkcentre E93 Firmware Versionfbktc5a
Lenovo ≫ Thinkcentre M4500k Firmware Versionfckt78a
Lenovo ≫ Thinkcentre M4500q Firmware Versionfhkt66a
Lenovo ≫ Thinkcentre M600 Firmware Versionm00kt44a
Lenovo ≫ Thinkcentre M610 Firmware Version-
Lenovo ≫ Thinkcentre M6600 Firmware Versionfwkt39a
Lenovo ≫ Thinkcentre M6600q Firmware Versionfwkt39a
Lenovo ≫ Thinkcentre M700 Firmware Versionm05kt54a
Lenovo ≫ Thinkcentre M715q Firmware Version-
Lenovo ≫ Thinkcentre M72e Firmware Versionf1kt71a
Lenovo ≫ Thinkcentre M73 Firmware Versionfckt78a
Lenovo ≫ Thinkcentre M73p Firmware Versionfbktc5a
Lenovo ≫ Thinkcentre M79 Firmware Versionm0lkt12a
Lenovo ≫ Thinkcentre M800 Firmware Versionfwkt39a
Lenovo ≫ Thinkcentre M83 Firmware Versionfbktcga
Lenovo ≫ Thinkcentre M900 Firmware Versionfwkt39a
Lenovo ≫ Thinkcentre M910q Firmware Version-
Lenovo ≫ Thinkcentre M910x Firmware Version-
Lenovo ≫ Thinkcentre M92 Firmware Version9skt95a
Lenovo ≫ Thinkcentre M92p Firmware Version9skt95a
Lenovo ≫ Thinkcentre M93 Firmware Versionfbktc5a
Lenovo ≫ Thinkcentre M93p Firmware Versionfbktc5a
Lenovo ≫ Yangtian Afh110 Firmware Versionm05kt73a
Lenovo ≫ Yangtian Afh81 Firmware Versionfckt80a
Lenovo ≫ Yangtian Afq150 Firmware Versionfwkt57a
Lenovo ≫ Yangtian Mc Carrizo-l Firmware Version-
Lenovo ≫ Yangtian Mc Godavari Firmware Versionm0lkt13a
Lenovo ≫ Yangtian Mc H110 Firmware Versionm05kt61a
Lenovo ≫ Yangtian Mc H81 Firmware Versionfckt80a
Lenovo ≫ Ideacentre 510s-23isu Firmware Versiono2ekt24a
Lenovo ≫ S200z Firmware Versionm09kt33a
Lenovo ≫ Thinkcentre E74z Firmware Versionfvkt48a
Lenovo ≫ Thinkcentre Edge 62z Firmware Versionf8kt40a
Lenovo ≫ Thinkcentre M700z Firmware Versionfvkt48a
Lenovo ≫ Thinkcentre M7200z Firmware Versionfgkt46a
Lenovo ≫ Thinkcentre M7250z Firmware Versionfgkt46a
Lenovo ≫ Thinkcentre M7300z Firmware Versionfvkt42a
Lenovo ≫ Thinkcentre M800z Firmware Versionfvkt42a
Lenovo ≫ Thinkcentre M810z Firmware Version-
Lenovo ≫ Thinkcentre M8200z Firmware Versionfgkt46a
Lenovo ≫ Thinkcentre M8250z Firmware Versionfgkt46a
Lenovo ≫ Thinkcentre M8300z Firmware Versionfvkt42a
Lenovo ≫ Thinkcentre M8350z Firmware Versionfvkt42a
Lenovo ≫ Thinkcentre M900z Firmware Versionfukt39a
Lenovo ≫ Thinkcentre M9500z Firmware Versionfukt44a
Lenovo ≫ Thinkcentre M9550z Firmware Versionfukt44a
Lenovo ≫ Thinkcentre X1 Aio Firmware Versionm0hkt32a
Lenovo ≫ Yangtian S3040 Firmware Versionfgkt49a
Lenovo ≫ Yangtian S800 Firmware Versionffkt43a
Lenovo ≫ Thinkserver Rd340 Firmware Version-
Lenovo ≫ Thinkserver Rd440 Firmware Versiona0tsb5a
Lenovo ≫ Thinkserver Rd540 Firmware Versiona1tsb5a
Lenovo ≫ Thinkserver Rd640 Firmware Versiona1tsb5a
Lenovo ≫ Thinkserver Rq750 Firmware Version7.05
Lenovo ≫ Thinkserver Rs140 Firmware Versionfbkt91c
Lenovo ≫ Thinkserver Td340 Firmware Versiona3tsb5a
Lenovo ≫ Thinkserver Ts140 Firmware Versionfbktc3a
Lenovo ≫ Thinkserver Ts150 Firmware Versionfbktc3a
Lenovo ≫ Thinkserver Ts240 Firmware Versionfbktc3a
Lenovo ≫ Thinkserver Ts250 Firmware Version-
Lenovo ≫ Thinkserver Ts450 Firmware Version-
Lenovo ≫ Thinkserver Ts550 Firmware Version-
Lenovo ≫ Thinkstation E31 Firmware Version9skt97a
Lenovo ≫ Thinkstation E32 Firmware Versionfbktc6a
Lenovo ≫ Thinkstation P300 Firmware Versionfbktc6a
Lenovo ≫ Thinkstation P310 Firmware Versionfwkt57a
Lenovo ≫ Thinkstation P320 Firmware Version-
Lenovo ≫ Thinkstation P410 Firmware Version-
Lenovo ≫ Thinkstation P500 Firmware Versiona4kt86a
Lenovo ≫ Thinkstation P510 Firmware Version-
Lenovo ≫ Thinkstation P700 Firmware Versiona5kt86a
Lenovo ≫ Thinkstation P710 Firmware Version-
Lenovo ≫ Thinkstation P900 Firmware Versiona6kt86a
Lenovo ≫ Thinkstation P910 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.125 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 0.9 | 5.9 |
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.