7.2

CVE-2021-4210

A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Data is provided by the National Vulnerability Database (NVD)
LenovoStadia Ggp-120 Firmware Version-
   LenovoStadia Ggp-120 Version-
LenovoThinkedge Se30 Firmware Version-
   LenovoThinkedge Se30 Version-
LenovoV540-24iwl Firmware Version-
   LenovoV540-24iwl Version-
LenovoThinkstation P520 Firmware Version-
   LenovoThinkstation P520 Version-
LenovoThinkstation P310 Firmware Version-
   LenovoThinkstation P310 Version-
LenovoV50t-13imb Firmware Version-
   LenovoV50t-13imb Version-
LenovoA540-27icb Firmware Version-
   LenovoA540-27icb Version-
LenovoA540-24icb Firmware Version-
   LenovoA540-24icb Version-
LenovoV410z Firmware Version-
   LenovoV410z Version-
LenovoThinkcentre M910z Firmware Version-
   LenovoThinkcentre M910z Version-
LenovoThinkcentre M70a Firmware Version-
   LenovoThinkcentre M70a Version-
LenovoThinkcentre M75n Firmware Version-
   LenovoThinkcentre M75n Version-
LenovoThinkcentre X1 Firmware Version-
   LenovoThinkcentre X1 Version-
LenovoThinkcentre M900 Firmware Version-
   LenovoThinkcentre M900 Version-
LenovoThinkcentre M810z Firmware Version-
   LenovoThinkcentre M810z Version-
LenovoThinkcentre M820z Firmware Version-
   LenovoThinkcentre M820z Version-
LenovoThinkcentre M900x Firmware Version-
   LenovoThinkcentre M900x Version-
LenovoThinkcentre M800 Firmware Version-
   LenovoThinkcentre M800 Version-
LenovoThinkcentre M700 Firmware Version-
   LenovoThinkcentre M700 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.3
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.