CVE-2020-8322: Medium severity lenovo 330-14ast firmware vulnerability

Published Jun 9, 2020
·
Updated

A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.

Affected Software

102 affected components
Lenovo 330-14ast Firmware
Lenovo 330-14ast
Lenovo 330-15ast Firmware
Lenovo 330-15ast
Lenovo 330-17ast Firmware
Lenovo 330-17ast
Lenovo 340c-15api Firmware
Lenovo 340c-15api
Lenovo 340c-15ast Firmware
Lenovo 340c-15ast
Lenovo 720s Touch-15ikb Firmware
Lenovo 720s Touch-15ikb
Lenovo 720s-15ikb Firmware
Lenovo 720s-15ikb
Lenovo 730s-13iwl Firmware
Lenovo 730s-13iwl
Lenovo C640-iml Firmware
Lenovo C640-iml
Lenovo E42-80 Firmware
Lenovo E42-80
Lenovo E52-80 Firmware
Lenovo E52-80
Lenovo K22-80 Firmware
Lenovo K22-80
Lenovo V720-12 Firmware
Lenovo V720-12
Lenovo K32-80 Kbl Firmware
Lenovo K32-80 Kbl
Lenovo K32-80 Skl Firmware
Lenovo K32-80 Skl
Lenovo Miix 720-12ikb Firmware
Lenovo Miix 720-12ikb
Lenovo S145-14api Firmware
Lenovo S145-14api
Lenovo S145-14ast Firmware
Lenovo S145-14ast
Lenovo S145-15api Firmware
Lenovo S145-15api
Lenovo S145-15ast Firmware
Lenovo S145-15ast
Lenovo S540-13api Firmware
Lenovo S540-13api
Lenovo S750-iil Firmware
Lenovo S750-iil
Lenovo S940-14iwl Firmware
Lenovo S940-14iwl
Lenovo Thinkbook 13s-iwl Firmware
Lenovo Thinkbook 13s-iwl
Lenovo Thinkbook 14s-iwl Firmware
Lenovo Thinkbook 14s-iwl
Lenovo V110-14ast Firmware
Lenovo V110-14ast
Lenovo V110-14ikb Firmware
Lenovo V110-14ikb
Lenovo V110-15ast Firmware
Lenovo V110-15ast
Lenovo V130-15igm Firmware
Lenovo V130-15igm
Lenovo V130-15ikb Firmware
Lenovo V130-15ikb
Lenovo V310-15igm Firmware
Lenovo V310-15igm
Lenovo V330-15igm Firmware
Lenovo V330-15igm
Lenovo V330-15ikb Firmware
Lenovo V330-15ikb
Lenovo V330-15isk Firmware
Lenovo V330-15isk
Lenovo V340-iil Firmware
Lenovo V340-iil
Lenovo V340-iml Firmware
Lenovo V340-iml
Lenovo V540s-13 Firmware
Lenovo V540s-13
Lenovo 14iwl Firmware
Lenovo 14iwl
Lenovo V730-13ikb Firmware
Lenovo V730-13ikb
Lenovo V730-13isk Firmware
Lenovo V730-13isk
Lenovo V730-15ikb Firmware
Lenovo V730-15ikb
Lenovo Wei5-15ikb Firmware
Lenovo Wei5-15ikb
Lenovo Xiaoxin 14-ast Qc 2019 Firmware
Lenovo Xiaoxin 14-ast Qc 2019
Lenovo Xx-14api Qc 2019 Firmware
Lenovo Xx-14api Qc 2019
Lenovo Yoga S730-13iwl Firmware
Lenovo Yoga S730-13iwl
Lenovo Yoga S940-14iwl Firmware
Lenovo Yoga S940-14iwl
Lenovo 6 Pro-13-iwl Firmware
Lenovo 6 Pro-13-iwl
Lenovo 6 Pro-14-iwl Firmware
Lenovo 6 Pro-14-iwl
Lenovo E53-80 Firmware
Lenovo E53-80
Lenovo K3 Firmware
Lenovo K3
Lenovo K4-iwl Firmware
Lenovo K4-iwl

Remediation

Information

Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-30042.

Event History

Jun 9, 2020
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
RemedyDescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-8322?

CVE-2020-8322 has a critical severity rating due to the potential for arbitrary code execution.

2

How do I fix CVE-2020-8322?

To resolve CVE-2020-8322, users should update the affected Lenovo firmware to the latest version provided by Lenovo.

3

Which Lenovo devices are affected by CVE-2020-8322?

CVE-2020-8322 affects specific models including the Lenovo 330-14AST, 330-15AST, and various others listed in Lenovo's security advisory.

4

What can happen if CVE-2020-8322 is exploited?

Exploitation of CVE-2020-8322 could allow an attacker to execute arbitrary code with elevated privileges on affected Lenovo devices.

5

Is there a workaround for CVE-2020-8322?

Currently, the best mitigation for CVE-2020-8322 is to apply the necessary firmware updates from Lenovo.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203