CVE-2020-8333: High severity lenovo 63 desktop firmware vulnerability
A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability CVE-2020-8333?
CVE-2020-8333 is a potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models that may allow arbitrary code execution.
Which Lenovo Desktops and ThinkStation models are affected by CVE-2020-8333?
CVE-2020-8333 affects Lenovo Desktops and ThinkStation models with Lenovo 63 Firmware, Lenovo H50-30g Firmware, Lenovo M4500 Firmware, Lenovo Qitian B4550 Firmware, Lenovo Qitian M4550 Firmware, Lenovo Thinkcentre E73 Firmware, Lenovo Thinkcentre E73s Firmware, Lenovo Thinkcentre E93 Firmware, Lenovo Thinkcentre M4500k Firmware, Lenovo Thinkcentre M4500q Firmware, Lenovo Thinkcentre M4500t Firmware, Lenovo Thinkcentre M4500s Firmware, Lenovo Yangtian Afh81 Firmware, Lenovo Yangtian Mc H81 Firmware, Lenovo Yangtian Mf H81 Pci Firmware, Lenovo Yangtian Wf H81 Pci Firmware, Lenovo Yangtian Tc H81 Pci Firmware, Lenovo Yangtian Wcc H81 Pci Firmware, Lenovo Thinkcentre M9350z Firmware, Lenovo Thinkcentre M93z Firmware, Lenovo Thinkstation E32 Firmware, Lenovo Thinkstation P300 Firmware, Lenovo Thinkstation S30 Firmware, Lenovo Thinkstation C30 Firmware, and Lenovo Thinkstation D30 Firmware.
What is the severity of CVE-2020-8333?
The severity of CVE-2020-8333 is high with a CVSS score of 7.8.
How can I fix CVE-2020-8333?
To fix CVE-2020-8333, it is recommended to apply the firmware updates provided by Lenovo. Please refer to the Lenovo Product Security Advisories for specific instructions.
Where can I find more information about CVE-2020-8333?
You can find more information about CVE-2020-8333 in the Lenovo Product Security Advisories.