CVE-2020-8332

MEDIUMCVSS 6.4/10EPSS 0.22%

Last modified

CVE-2020-8332 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.

Description

A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.

Metrics

CVSS 3.1
6.4/10

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.22%

12.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoBladecenter Hs23 Firmware< tke170b
LenovoBladecenter Hs23e Firmware< ahe172b
LenovoCompute Node-X440 Firmware< cge128a
LenovoFlex System X220 Firmware< kse170b
LenovoFlex System X240 Firmware< b2e172b
LenovoFlex System X440 Firmware< cne172b
LenovoNextscale Nx360 M4 Firmware< fhe132b
LenovoSystem X3300 M4 Firmware< yae166b
LenovoSystem X3500 M4 Firmware< y5e170b
LenovoSystem X3530 M4 Firmware< bee174b
LenovoSystem X3550 M4 Firmware< d7e174b
LenovoSystem X3630 M4 Firmware< bee174b
LenovoSystem X3650 M4 Firmware< vve172b
LenovoSystem X3650 M4 Bd Firmware< vve172b
LenovoSystem X3650 M4 Hd Firmware< vve172b
LenovoSystem X3750 M4 Firmware< a5e130a
LenovoSystem X3750 M4 Firmware< koe170b
LenovoIdataplex Dx360 M4 Firmware< tde168b
LenovoIdataplex Dx360 M4 Water Cooled Firmware< tde168b

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-8332?
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
How severe is CVE-2020-8332?
CVE-2020-8332 has a CVSS score of 6.4/10 (MEDIUM severity). The EPSS model estimates a 0.22% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8332?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-8332?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST