ZeroHour

CVE-2021-4210

CVSS 3.1
6.7 medium
EPSS
<1%p16
Published
()
Modified
Description

A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Vendors
lenovo
Products
stadia ggp-120 firmware, thinkedge se30 firmware, v540-24iwl firmware, thinkstation p520 firmware, thinkstation p310 firmware, v50t-13imb firmware, thinkstation p520c firmware, a540-27icb firmware, a540-24icb firmware, ideacentre g5-14imb05 firmware, v410z firmware, thinkcentre m910z firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.