VulnerabilityModified
CVE-2021-4210
A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
MEDIUM 6.7EPSS 0.26%
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- lenovo/stadia ggp-120 firmware · lenovo/thinkedge se30 firmware · lenovo/v540-24iwl firmware · lenovo/thinkstation p520 firmware · lenovo/thinkstation p310 firmware · lenovo/v50t-13imb firmware · lenovo/thinkstation p520c firmware · lenovo/a540-27icb firmware · lenovo/a540-24icb firmware · lenovo/ideacentre g5-14imb05 firmware · lenovo/v410z firmware · lenovo/thinkcentre m910z firmware · lenovo/thinkcentre m70a firmware · lenovo/thinkcentre m75n firmware · lenovo/thinkcentre x1 firmware · lenovo/thinkcentre m900 firmware · lenovo/thinkcentre m810z firmware · lenovo/thinkcentre m90a gen2 firmware · lenovo/thinkcentre m820z firmware · lenovo/ideacentre aio 3-27itl6 firmware · +12 more
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-77639Patch, Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-77639Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.