6.9

CVE-2017-3775

Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.

Data is provided by the National Vulnerability Database (NVD)
LenovoFlex System X240 M5 Bios Version < 2.61
   LenovoFlex System X240 M5 Version-
LenovoFlex System X280 X6 Bios Version < 4.21
   LenovoFlex System X280 X6 Version-
LenovoFlex System X480 X6 Bios Version < 4.21
   LenovoFlex System X480 X6 Version-
LenovoFlex System X880 Bios Version < 4.21
   LenovoFlex System X880 Version-
LenovoNextscale Nx360 M5 Bios Version < 2.61
   LenovoNextscale Nx360 M5 Version-
LenovoSystem X3250 M6 Bios Version < 2.23
   LenovoSystem X3250 M6 Version-
LenovoSystem X3500 M5 Bios Version < 2.61
   LenovoSystem X3500 M5 Version-
LenovoSystem X3550 M5 Bios Version < 2.61
   LenovoSystem X3550 M5 Version-
LenovoSystem X3650 M5 Bios Version < 2.61
   LenovoSystem X3650 M5 Version-
LenovoSystem X3850 X6 Bios Version < 4.3
   LenovoSystem X3850 X6 Version-
LenovoSystem X3950 X6 Bios Version < 4.3
   LenovoSystem X3950 X6 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.094
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 0.5 5.9
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.