7.8

CVE-2020-8333

A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution

Data is provided by the National Vulnerability Database (NVD)
Lenovo63 Firmware Version < fckt98a
   Lenovo63 Version-
LenovoH50-30g Firmware Version < fckt98a
   LenovoH50-30g Version-
LenovoM4500 Firmware Version < fckt98a
   LenovoM4500 Version-
LenovoM4550 Firmware Version < fckt98a
   LenovoM4550 Version-
LenovoQitian 4500 Firmware Version < fckt98a
   LenovoQitian 4500 Version-
LenovoQitian B4550 Firmware Version < fckt98a
   LenovoQitian B4550 Version-
LenovoQitian M4550 Firmware Version < fckt98a
   LenovoQitian M4550 Version-
LenovoThinkcentre E73 Firmware Version < fckt98a
   LenovoThinkcentre E73 Version-
LenovoThinkcentre E73s Firmware Version < fckt98a
   LenovoThinkcentre E73s Version-
LenovoThinkcentre E93 Firmware Version < fbktdea
   LenovoThinkcentre E93 Version-
LenovoThinkcentre M4500k Firmware Version < fckt98a
   LenovoThinkcentre M4500k Version-
LenovoThinkcentre M4500q Firmware Version < fhkt85a
   LenovoThinkcentre M4500q Version-
LenovoThinkcentre M4500t Firmware Version < fckt98a
   LenovoThinkcentre M4500t Version-
LenovoThinkcentre M4500s Firmware Version < fckt98a
   LenovoThinkcentre M4500s Version-
LenovoYangtian Afh81 Firmware Version < fckt98a
   LenovoYangtian Afh81 Version-
LenovoYangtian Mc H81 Firmware Version < fckt98a
   LenovoYangtian Mc H81 Version-
LenovoYangtian Mf H81 Pci Firmware Version < fckt98a
   LenovoYangtian Mf H81 Pci Version-
LenovoYangtian Wf H81 Pci Firmware Version < fckt98a
   LenovoYangtian Wf H81 Pci Version-
LenovoYangtian Tc H81 Pci Firmware Version < fckt98a
   LenovoYangtian Tc H81 Pci Version-
LenovoYangtian Wcc H81 Pci Firmware Version < fckt98a
   LenovoYangtian Wcc H81 Pci Version-
LenovoThinkcentre M9350z Firmware Version < fekta2a
   LenovoThinkcentre M9350z Version-
LenovoThinkcentre M93z Firmware Version < fekta2a
   LenovoThinkcentre M93z Version-
LenovoThinkstation C30 Firmware Version < a3kt70a
   LenovoThinkstation C30 Version-
LenovoThinkstation D30 Firmware Version < a3kt70a
   LenovoThinkstation D30 Version-
LenovoThinkstation E32 Firmware Version < fbktdea
   LenovoThinkstation E32 Version-
LenovoThinkstation P300 Firmware Version < a2kt70a
   LenovoThinkstation P300 Version-
LenovoThinkstation S30 Firmware Version < a2kt70a
   LenovoThinkstation S30 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.081
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
psirt@lenovo.com 6.4 0.5 5.9
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H