7.2

CVE-2021-4211

A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LenovoA340-22icb Firmware Version-
   LenovoA340-22icb Version-
LenovoA340-22ick Firmware Version-
   LenovoA340-22ick Version-
LenovoA340-24icb Firmware Version-
   LenovoA340-24icb Version-
LenovoA340-24ick Firmware Version-
   LenovoA340-24ick Version-
LenovoA540-24icb Firmware Version-
   LenovoA540-24icb Version-
LenovoA540-27icb Firmware Version-
   LenovoA540-27icb Version-
LenovoSe30 Firmware Version-
   LenovoSe30 Version-
LenovoThinkcentre M600 Firmware Version-
   LenovoThinkcentre M600 Version-
LenovoThinkcentre M70a Firmware Version-
   LenovoThinkcentre M70a Version-
LenovoThinkcentre M710e Firmware Version-
   LenovoThinkcentre M710e Version-
LenovoThinkcentre M710q Firmware Version-
   LenovoThinkcentre M710q Version-
LenovoThinkcentre M710s Firmware Version-
   LenovoThinkcentre M710s Version-
LenovoThinkcentre M710t Firmware Version-
   LenovoThinkcentre M710t Version-
LenovoThinkcentre M720e Firmware Version-
   LenovoThinkcentre M720e Version-
LenovoThinkcentre M75n Firmware Version-
   LenovoThinkcentre M75n Version-
LenovoThinkcentre M800 Firmware Version-
   LenovoThinkcentre M800 Version-
LenovoThinkcentre M810z Firmware Version-
   LenovoThinkcentre M810z Version-
LenovoThinkcentre M820z Firmware Version-
   LenovoThinkcentre M820z Version-
LenovoThinkcentre M900 Firmware Version-
   LenovoThinkcentre M900 Version-
LenovoThinkcentre M900x Firmware Version-
   LenovoThinkcentre M900x Version-
LenovoThinkcentre M910q Firmware Version-
   LenovoThinkcentre M910q Version-
LenovoThinkcentre M910s Firmware Version-
   LenovoThinkcentre M910s Version-
LenovoThinkcentre M910t Firmware Version-
   LenovoThinkcentre M910t Version-
LenovoThinkcentre M910x Firmware Version-
   LenovoThinkcentre M910x Version-
LenovoThinkstation P310 Firmware Version-
   LenovoThinkstation P310 Version-
LenovoThinkstation P320 Firmware Version-
   LenovoThinkstation P320 Version-
LenovoV30a-22iml Firmware Version-
   LenovoV30a-22iml Version-
LenovoV30a-24iml Firmware Version-
   LenovoV30a-24iml Version-
LenovoV410z Firmware Version-
   LenovoV410z Version-
LenovoV50t-13iob G2 Firmware Version-
   LenovoV50t-13iob G2 Version-
LenovoV520 Firmware Version-
   LenovoV520 Version-
LenovoV520s Firmware Version-
   LenovoV520s Version-
LenovoV530-15icb Firmware Version-
   LenovoV530-15icb Version-
LenovoV530-15icr Firmware Version-
   LenovoV530-15icr Version-
LenovoV530s-07icb Firmware Version-
   LenovoV530s-07icb Version-
LenovoV530s-07icr Firmware Version-
   LenovoV530s-07icr Version-
LenovoV540-24iwl Firmware Version-
   LenovoV540-24iwl Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.108
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.