7.2
CVE-2021-4210
- EPSS 0.11%
- Published 22.04.2022 21:15:09
- Last modified 21.11.2024 06:37:09
- Source psirt@lenovo.com
- Teams watchlist Login
- Open Login
A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Data is provided by the National Vulnerability Database (NVD)
Lenovo ≫ Stadia Ggp-120 Firmware Version-
Lenovo ≫ Thinkedge Se30 Firmware Version-
Lenovo ≫ V540-24iwl Firmware Version-
Lenovo ≫ Thinkstation P520 Firmware Version-
Lenovo ≫ Thinkstation P310 Firmware Version-
Lenovo ≫ V50t-13imb Firmware Version-
Lenovo ≫ Thinkstation P520c Firmware Version-
Lenovo ≫ A540-27icb Firmware Version-
Lenovo ≫ A540-24icb Firmware Version-
Lenovo ≫ Ideacentre G5-14imb05 Firmware Version-
Lenovo ≫ V410z Firmware Version-
Lenovo ≫ Thinkcentre M910z Firmware Version-
Lenovo ≫ Thinkcentre M70a Firmware Version-
Lenovo ≫ Thinkcentre M75n Firmware Version-
Lenovo ≫ Thinkcentre X1 Firmware Version-
Lenovo ≫ Thinkcentre M900 Firmware Version-
Lenovo ≫ Thinkcentre M810z Firmware Version-
Lenovo ≫ Thinkcentre M90a Gen2 Firmware Version-
Lenovo ≫ Thinkcentre M820z Firmware Version-
Lenovo ≫ Ideacentre Aio 3-27itl6 Firmware Version-
Lenovo ≫ Ideacentre Aio 3-24itl6 Firmware Version-
Lenovo ≫ Thinkcentre M900x Firmware Version-
Lenovo ≫ Thinkcentre M800 Firmware Version-
Lenovo ≫ Ideacentre Aio 3-24iil5 Firmware Version-
Lenovo ≫ Thinkcentre M700 Firmware Version-
Lenovo ≫ Thinkcentre M700 Tiny Firmware Version-
Lenovo ≫ Ideacentre Aio 3-24ada6 Firmware Version-
Lenovo ≫ Ideacentre Aio 3-22itl6 Firmware Version-
Lenovo ≫ Ideacentre Aio 3-22iil5 Firmware Version-
Lenovo ≫ Ideacentre Aio 3-22ada6 Firmware Version-
Lenovo ≫ Ideacentre 5-14imb05 Firmware Version-
Lenovo ≫ Ideacentre C5-14imb05 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.3 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
psirt@lenovo.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.