First published: Thu Sep 24 2020(Updated: )
A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo 63 Firmware | <fckt98a | |
Lenovo 63 | ||
Lenovo H50-30g Firmware | <fckt98a | |
Lenovo H50-30g | ||
Lenovo M4500 Firmware | <fckt98a | |
Lenovo M4500 | ||
<fckt98a | ||
Lenovo Qitian 4500 Firmware | <fckt98a | |
Lenovo Qitian 4500 | ||
Lenovo Qitian B4550 Firmware | <fckt98a | |
Lenovo Qitian B4550 | ||
Lenovo Qitian M4550 Firmware | <fckt98a | |
Lenovo Qitian M4550 | ||
Lenovo Thinkcentre E73 Firmware | <fckt98a | |
Lenovo Thinkcentre E73 | ||
Lenovo Thinkcentre E73s Firmware | <fckt98a | |
Lenovo Thinkcentre E73s | ||
Lenovo Thinkcentre E93 Firmware | <fbktdea | |
Lenovo ThinkCentre E93 | ||
Lenovo Thinkcentre M4500k Firmware | <fckt98a | |
Lenovo Thinkcentre M4500k | ||
Lenovo Thinkcentre M4500q Firmware | <fhkt85a | |
Lenovo Thinkcentre M4500q | ||
Lenovo Thinkcentre M4500t Firmware | <fckt98a | |
Lenovo Thinkcentre M4500t | ||
Lenovo Thinkcentre M4500s Firmware | <fckt98a | |
Lenovo Thinkcentre M4500s | ||
Lenovo Yangtian Afh81 Firmware | <fckt98a | |
Lenovo Yangtian Afh81 | ||
Lenovo Yangtian Mc H81 Firmware | <fckt98a | |
Lenovo Yangtian Mc H81 | ||
Lenovo Yangtian Mf H81 Pci Firmware | <fckt98a | |
Lenovo Yangtian Mf H81 Pci | ||
Lenovo Yangtian Wf H81 Pci Firmware | <fckt98a | |
Lenovo Yangtian Wf H81 Pci | ||
Lenovo Yangtian Tc H81 Pci Firmware | <fckt98a | |
Lenovo Yangtian Tc H81 Pci | ||
Lenovo Yangtian Wcc H81 Pci Firmware | <fckt98a | |
Lenovo Yangtian Wcc H81 Pci | ||
Lenovo Thinkcentre M9350z Firmware | <fekta2a | |
Lenovo Thinkcentre M9350z | ||
Lenovo Thinkcentre M93z Firmware | <fekta2a | |
Lenovo Thinkcentre M93z | ||
<a3kt70a | ||
<a3kt70a | ||
Lenovo Thinkstation E32 Firmware | <fbktdea | |
Lenovo Thinkstation E32 | ||
Lenovo Thinkstation P300 Firmware | <a2kt70a | |
Lenovo Thinkstation P300 | ||
<a2kt70a | ||
Update system firmware to the version (or newer) indicated for your model in the Product Impact section of LEN-30042.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8333 is a potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models that may allow arbitrary code execution.
CVE-2020-8333 affects Lenovo Desktops and ThinkStation models with Lenovo 63 Firmware, Lenovo H50-30g Firmware, Lenovo M4500 Firmware, Lenovo Qitian B4550 Firmware, Lenovo Qitian M4550 Firmware, Lenovo Thinkcentre E73 Firmware, Lenovo Thinkcentre E73s Firmware, Lenovo Thinkcentre E93 Firmware, Lenovo Thinkcentre M4500k Firmware, Lenovo Thinkcentre M4500q Firmware, Lenovo Thinkcentre M4500t Firmware, Lenovo Thinkcentre M4500s Firmware, Lenovo Yangtian Afh81 Firmware, Lenovo Yangtian Mc H81 Firmware, Lenovo Yangtian Mf H81 Pci Firmware, Lenovo Yangtian Wf H81 Pci Firmware, Lenovo Yangtian Tc H81 Pci Firmware, Lenovo Yangtian Wcc H81 Pci Firmware, Lenovo Thinkcentre M9350z Firmware, Lenovo Thinkcentre M93z Firmware, Lenovo Thinkstation E32 Firmware, Lenovo Thinkstation P300 Firmware, Lenovo Thinkstation S30 Firmware, Lenovo Thinkstation C30 Firmware, and Lenovo Thinkstation D30 Firmware.
The severity of CVE-2020-8333 is high with a CVSS score of 7.8.
To fix CVE-2020-8333, it is recommended to apply the firmware updates provided by Lenovo. Please refer to the Lenovo Product Security Advisories for specific instructions.
You can find more information about CVE-2020-8333 in the Lenovo Product Security Advisories.