6.7

CVE-2024-4550

A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerlenovo
Produkt thinkstation_p360_workstation_firmware
Default Statusunaffected
Version 0
Version < s0ekt43a
Status affected
Herstellerlenovo
Produkt thinksystem_st50_firmware
Default Statusunaffected
Version 0
Version < ite134a
Status affected
Herstellerlenovo
Produkt thinksystem_st50_v2_firmware
Default Statusunaffected
Version 0
Version < toe112d
Status affected
Herstellerlenovo
Produkt thinksystem_st58_v2_firmware
Default Statusunaffected
Version 0
Version < toe112d
Status affected
Herstellerlenovo
Produkt thinksystem_st58_firmware
Default Statusunaffected
Version 0
Version < ite134a
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@lenovo.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).