First published: Fri May 04 2018(Updated: )
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Flex System X240 M5 | <2.61 | |
Lenovo Flex System X240 M5 Bios | ||
Lenovo Flex System X280 X6 | <4.21 | |
Lenovo Flex System X280 X6 Firmware | ||
Lenovo Flex System X480 X6 BIOS | <4.21 | |
Lenovo Flex System X480 X6 BIOS | ||
Lenovo Flex System X880 X6 Bios | <4.21 | |
Lenovo Flex System X880 BIOS | ||
Lenovo Nextscale Nx360 M5 Bios | <2.61 | |
Lenovo NextScale NX360 M5 | ||
Lenovo System X3250 M6 | <2.23 | |
Lenovo System X3250 M6 Firmware | ||
Lenovo Flex System X3500 M5 | <2.61 | |
Lenovo System X3500 M5 | ||
Lenovo System X3550 M5 | <2.61 | |
Lenovo System X3550 M5 | ||
Lenovo System x3650 M5 | <2.61 | |
Lenovo System x3650 M5 | ||
Lenovo System X3850 X6 Firmware | <4.3 | |
Lenovo System X3850 X6 | ||
Lenovo System X3950 X6 Firmware | <4.3 | |
Lenovo System X3950 X6 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3775 has a medium severity due to its potential for an attacker to boot unsigned code with physical access.
To fix CVE-2017-3775, update the BIOS/UEFI to a version that addresses the issue and ensures proper authentication of signed code.
CVE-2017-3775 affects several Lenovo System x server BIOS/UEFI versions including Flex System X240 M5, X280 X6, X480 X6, and others.
Yes, exploiting CVE-2017-3775 requires physical access to the system to boot unsigned code.
CVE-2017-3775 poses a risk of an attacker executing unauthorized code in a secured environment, compromising the integrity of the system.