First published: Thu Oct 26 2017(Updated: )
System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing BIOS/UEFI initialization process.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo ThinkCentre M710t/s Firmware | <m16kt40a | |
Lenovo ThinkCentre M710s Firmware | ||
Lenovo Ideacentre M710t Firmware | <m16kt40a | |
Lenovo ThinkCentre M710t/s | ||
Lenovo AIO E95 | <m16kt40a | |
Lenovo AIO E95 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3771 has been classified as a medium severity vulnerability due to its impact on system security during the boot process.
To remediate CVE-2017-3771, ensure that your Lenovo E95 or ThinkCentre M710s/M710t systems complete the BIOS/UEFI initialization process.
CVE-2017-3771 affects the Lenovo E95, ThinkCentre M710s, and ThinkCentre M710t systems shipped without completed BIOS/UEFI setup.
The potential risk of CVE-2017-3771 includes unauthorized access or control over systems during the boot phase.
As of now, no specific patch has been publicly available for CVE-2017-3771, but following the initialization process will help mitigate the issue.