CVE Feed

    Dashboard / CVE / CVE-2020-8332

    CVE-2020-8332

    A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.

    Published:Oct 14, 2020
    Last Modified:Nov 21, 2024
    EPS:Oct 14, 2020
    EPSS Score:0.00035
    CVSS Score:6.4

    Affected Products

    Vendor
    Lenovo
    Product
    Bladecenter Hs23
    Vendor
    Lenovo
    Product
    Bladecenter Hs23 Firmware
    Vendor
    Lenovo
    Product
    Bladecenter Hs23e
    Vendor
    Lenovo
    Product
    Bladecenter Hs23e Firmware
    Vendor
    Lenovo
    Product
    Compute Node-x440
    Vendor
    Lenovo
    Product
    Compute Node-x440 Firmware
    Vendor
    Lenovo
    Product
    Flex System X220
    Vendor
    Lenovo
    Product
    Flex System X220 Firmware
    Vendor
    Lenovo
    Product
    Flex System X240
    Vendor
    Lenovo
    Product
    Flex System X240 Firmware
    Vendor
    Lenovo
    Product
    Flex System X440
    Vendor
    Lenovo
    Product
    Flex System X440 Firmware
    Vendor
    Lenovo
    Product
    Idataplex Dx360 M4
    Vendor
    Lenovo
    Product
    Idataplex Dx360 M4 Firmware
    Vendor
    Lenovo
    Product
    Idataplex Dx360 M4 Water Cooled
    Vendor
    Lenovo
    Product
    Idataplex Dx360 M4 Water Cooled Firmware
    Vendor
    Lenovo
    Product
    Nextscale Nx360 M4
    Vendor
    Lenovo
    Product
    Nextscale Nx360 M4 Firmware
    Vendor
    Lenovo
    Product
    System X3300 M4
    Vendor
    Lenovo
    Product
    System X3300 M4 Firmware
    Vendor
    Lenovo
    Product
    System X3500 M4
    Vendor
    Lenovo
    Product
    System X3500 M4 Firmware
    Vendor
    Lenovo
    Product
    System X3530 M4
    Vendor
    Lenovo
    Product
    System X3530 M4 Firmware
    Vendor
    Lenovo
    Product
    System X3550 M4
    Vendor
    Lenovo
    Product
    System X3550 M4 Firmware
    Vendor
    Lenovo
    Product
    System X3630 M4
    Vendor
    Lenovo
    Product
    System X3630 M4 Firmware
    Vendor
    Lenovo
    Product
    System X3650 M4
    Vendor
    Lenovo
    Product
    System X3650 M4 Bd
    Vendor
    Lenovo
    Product
    System X3650 M4 Bd Firmware
    Vendor
    Lenovo
    Product
    System X3650 M4 Firmware
    Vendor
    Lenovo
    Product
    System X3650 M4 Hd
    Vendor
    Lenovo
    Product
    System X3650 M4 Hd Firmware
    Vendor
    Lenovo
    Product
    System X3750 M4
    Vendor
    Lenovo
    Product
    System X3750 M4 Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High