CVE-2020-8323
MEDIUMCVSS 6.7/10EPSS 0.31%
Last modified
CVE-2020-8323 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | 330-14ast Firmware | All versions |
| Lenovo | 330-15ast Firmware | All versions |
| Lenovo | 330-17ast Firmware | All versions |
| Lenovo | 340c-15api Firmware | All versions |
| Lenovo | 340c-15ast Firmware | All versions |
| Lenovo | 720s Touch-15ikb Firmware | All versions |
| Lenovo | 720s-15ikb Firmware | All versions |
| Lenovo | 730s-13iwl Firmware | All versions |
| Lenovo | C640-Iml Firmware | All versions |
| Lenovo | E42-80 Firmware | All versions |
| Lenovo | E52-80 Firmware | All versions |
| Lenovo | K22-80 Firmware | All versions |
| Lenovo | V720-12 Firmware | All versions |
| Lenovo | K32-80 Kbl Firmware | All versions |
| Lenovo | K32-80 Skl Firmware | All versions |
| Lenovo | Miix 720-12ikb Firmware | All versions |
| Lenovo | S145-14api Firmware | All versions |
| Lenovo | S145-14ast Firmware | All versions |
| Lenovo | S145-15api Firmware | All versions |
| Lenovo | S145-15ast Firmware | All versions |
| Lenovo | S540-13api Firmware | All versions |
| Lenovo | S750-Iil Firmware | All versions |
| Lenovo | S940-14iwl Firmware | All versions |
| Lenovo | Thinkbook 13s-Iwl Firmware | All versions |
| Lenovo | Thinkbook 14s-Iwl Firmware | All versions |
| Lenovo | V110-14ast Firmware | All versions |
| Lenovo | V110-14ikb Firmware | All versions |
| Lenovo | V110-15ast Firmware | All versions |
| Lenovo | V130-15igm Firmware | All versions |
| Lenovo | V130-15ikb Firmware | All versions |
| Lenovo | V310-15igm Firmware | All versions |
| Lenovo | V330-15igm Firmware | All versions |
| Lenovo | V330-15ikb Firmware | All versions |
| Lenovo | V330-15isk Firmware | All versions |
| Lenovo | V340-Iil Firmware | All versions |
| Lenovo | V340-Iml Firmware | All versions |
| Lenovo | V540s-13 Firmware | All versions |
| Lenovo | 14iwl Firmware | All versions |
| Lenovo | V730-13ikb Firmware | All versions |
| Lenovo | V730-13isk Firmware | All versions |
| Lenovo | V730-15ikb Firmware | All versions |
| Lenovo | Wei5-15ikb Firmware | All versions |
| Lenovo | Xiaoxin 14-Ast Qc 2019 Firmware | All versions |
| Lenovo | Xx-14api Qc 2019 Firmware | All versions |
| Lenovo | Yoga S730-13iwl Firmware | All versions |
| Lenovo | Yoga S940-14iwl Firmware | All versions |
| Lenovo | 6 Pro-13-Iwl Firmware | All versions |
| Lenovo | 6 Pro-14-Iwl Firmware | All versions |
| Lenovo | E53-80 Firmware | All versions |
| Lenovo | K3 Firmware | All versions |
Showing 50 of 172 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-30042Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8323?
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
How severe is CVE-2020-8323?
CVE-2020-8323 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.31% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8323?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8317A DLL search path vulnerability was reported in Lenovo Drive…7.8
- CVE-2020-8318A privilege escalation vulnerability was reported in the Len…7.8
- CVE-2020-8319A privilege escalation vulnerability was reported in Lenovo …7.8
- CVE-2020-8320An internal shell was included in BIOS image in some ThinkPa…6.8
- CVE-2020-8321A potential vulnerability in the SMI callback function used …6.7
- CVE-2020-8322A potential vulnerability in the SMI callback function used …6.7
- CVE-2020-8324A vulnerability was reported in LenovoAppScenarioPluginSyste…5.5
- CVE-2020-8325Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-8326An unquoted service path vulnerability was reported in Lenov…7.8
- CVE-2020-8327A privilege escalation vulnerability was reported in LenovoB…7.8
- CVE-2020-8328Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-8329A denial of service vulnerability was reported in the firmwa…7.5
Are you affected by CVE-2020-8323?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
