CVE-2017-3775: Medium severity Lenovo Flex System X240 M5 Bios vulnerability
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3775?
CVE-2017-3775 has a medium severity due to its potential for an attacker to boot unsigned code with physical access.
How do I fix CVE-2017-3775?
To fix CVE-2017-3775, update the BIOS/UEFI to a version that addresses the issue and ensures proper authentication of signed code.
Which Lenovo products are affected by CVE-2017-3775?
CVE-2017-3775 affects several Lenovo System x server BIOS/UEFI versions including Flex System X240 M5, X280 X6, X480 X6, and others.
Is physically accessing the system necessary to exploit CVE-2017-3775?
Yes, exploiting CVE-2017-3775 requires physical access to the system to boot unsigned code.
What security risk does CVE-2017-3775 pose?
CVE-2017-3775 poses a risk of an attacker executing unauthorized code in a secured environment, compromising the integrity of the system.