6.9

CVE-2020-8332

A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.

Data is provided by the National Vulnerability Database (NVD)
LenovoBladecenter Hs23 Firmware Version < tke170b
   LenovoBladecenter Hs23 Version-
LenovoBladecenter Hs23e Firmware Version < ahe172b
   LenovoBladecenter Hs23e Version-
LenovoCompute Node-x440 Firmware Version < cge128a
   LenovoCompute Node-x440 Version-
LenovoFlex System X220 Firmware Version < kse170b
   LenovoFlex System X220 Version-
LenovoFlex System X240 Firmware Version < b2e172b
   LenovoFlex System X240 Version-
LenovoFlex System X440 Firmware Version < cne172b
   LenovoFlex System X440 Version-
LenovoNextscale Nx360 M4 Firmware Version < fhe132b
   LenovoNextscale Nx360 M4 Version-
LenovoSystem X3300 M4 Firmware Version < yae166b
   LenovoSystem X3300 M4 Version-
LenovoSystem X3500 M4 Firmware Version < y5e170b
   LenovoSystem X3500 M4 Version-
LenovoSystem X3530 M4 Firmware Version < bee174b
   LenovoSystem X3530 M4 Version-
LenovoSystem X3550 M4 Firmware Version < d7e174b
   LenovoSystem X3550 M4 Version-
LenovoSystem X3630 M4 Firmware Version < bee174b
   LenovoSystem X3630 M4 Version-
LenovoSystem X3650 M4 Firmware Version < vve172b
   LenovoSystem X3650 M4 Version-
LenovoSystem X3650 M4 Bd Firmware Version < vve172b
   LenovoSystem X3650 M4 Bd Version-
LenovoSystem X3650 M4 Hd Firmware Version < vve172b
   LenovoSystem X3650 M4 Hd Version-
LenovoSystem X3750 M4 Firmware Version < a5e130a
   LenovoSystem X3750 M4 Version-
LenovoSystem X3750 M4 Firmware Version < koe170b
   LenovoSystem X3750 M4 Version-
LenovoIdataplex Dx360 M4 Firmware Version < tde168b
   LenovoIdataplex Dx360 M4 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.065
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 0.5 5.9
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
psirt@lenovo.com 6.4 0.5 5.9
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.