First published: Thu Jan 26 2017(Updated: )
The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Flex System X240 M5 | ||
Lenovo Flex System X280 M6 Bios | ||
Lenovo Flex System X480 X6 BIOS | ||
Lenovo Flex System X880 X6 BIOS | ||
Lenovo Nextscale Nx360 M5 Bios | ||
Lenovo System X3250 M6 | ||
Lenovo Flex System X3500 M5 | ||
Lenovo System X3550 M5 | ||
Lenovo System x3650 M5 | ||
Lenovo System X3850 X6 Firmware | ||
Lenovo System X3950 X6 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8226 has a medium severity level due to its potential to cause a denial of service.
To fix CVE-2016-8226, update the BIOS of the affected Lenovo systems to the latest version provided by Lenovo.
CVE-2016-8226 affects Lenovo System X M5, M6, X6 models, including Flex System and Nextscale series.
CVE-2016-8226 is a denial of service vulnerability that can be exploited by manipulating a UEFI data structure.
CVE-2016-8226 requires physical access to the system to exploit, as it involves updating BIOS settings.