47
CVE-2017-3775
—CVSS 3.0
6.4 medium
EPSS
<1%p19
Published
()
Modified
Description
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.
- Vendors
- lenovo
- Products
- flex system x240 m5 bios, flex system x280 x6 bios, flex system x480 x6 bios, flex system x880 bios, nextscale nx360 m5 bios, system x3250 m6 bios, system x3500 m5 bios, system x3550 m5 bios, system x3650 m5 bios, system x3850 x6 bios, system x3950 x6 bios
- Weakness
- CWE-287
- Vector
- CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H