ZeroHour

CVE-2020-8332

CVSS 3.1
6.4 medium
EPSS
<1%p14
Published
()
Modified
Description

A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.

Vendors
lenovo
Products
bladecenter hs23 firmware, bladecenter hs23e firmware, compute node-x440 firmware, flex system x220 firmware, flex system x240 firmware, flex system x440 firmware, nextscale nx360 m4 firmware, system x3300 m4 firmware, system x3500 m4 firmware, system x3530 m4 firmware, system x3550 m4 firmware, system x3630 m4 firmware
Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.