ZeroHour

CVE-2017-3775

CVSS 3.0
6.4 medium
EPSS
<1%p19
Published
()
Modified
Description

Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.

Vendors
lenovo
Products
flex system x240 m5 bios, flex system x280 x6 bios, flex system x480 x6 bios, flex system x880 bios, nextscale nx360 m5 bios, system x3250 m6 bios, system x3500 m5 bios, system x3550 m5 bios, system x3650 m5 bios, system x3850 x6 bios, system x3950 x6 bios
Weakness
CWE-287
Vector
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news