VulnerabilityModified
CVE-2021-4211
A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
MEDIUM 6.7EPSS 0.26%
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- lenovo/a340-22icb firmware · lenovo/a340-22ick firmware · lenovo/a340-24icb firmware · lenovo/a340-24ick firmware · lenovo/a540-24icb firmware · lenovo/a540-27icb firmware · lenovo/ideacentre 5-14iob6 firmware · lenovo/ideacentre 510s-07icb firmware · lenovo/ideacentre 510s-07ick firmware · lenovo/ideacentre aio 3-22ada6 firmware · lenovo/ideacentre aio 3-22iil5 firmware · lenovo/ideacentre aio 3-22itl6 firmware · lenovo/ideacentre aio 3-24ada6 firmware · lenovo/ideacentre aio 3-24iil5 firmware · lenovo/ideacentre aio 3-24itl6 firmware · lenovo/ideacentre aio 3-27itl6 firmware · lenovo/ideacentre creator 5-14iob6 firmware · lenovo/ideacentre gaming 5-14iob6 firmware · lenovo/se30 firmware · lenovo/thinkcentre m600 firmware · +33 more
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-77639Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-77639Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.