CVE-2021-4210
Last modified
CVE-2021-4210 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Stadia Ggp-120 Firmware | All versions |
| Lenovo | Thinkedge Se30 Firmware | All versions |
| Lenovo | V540-24iwl Firmware | All versions |
| Lenovo | Thinkstation P520 Firmware | All versions |
| Lenovo | Thinkstation P310 Firmware | All versions |
| Lenovo | V50t-13imb Firmware | All versions |
| Lenovo | Thinkstation P520c Firmware | All versions |
| Lenovo | A540-27icb Firmware | All versions |
| Lenovo | A540-24icb Firmware | All versions |
| Lenovo | Ideacentre G5-14imb05 Firmware | All versions |
| Lenovo | V410z Firmware | All versions |
| Lenovo | Thinkcentre M910z Firmware | All versions |
| Lenovo | Thinkcentre M70a Firmware | All versions |
| Lenovo | Thinkcentre M75n Firmware | All versions |
| Lenovo | Thinkcentre X1 Firmware | All versions |
| Lenovo | Thinkcentre M900 Firmware | All versions |
| Lenovo | Thinkcentre M810z Firmware | All versions |
| Lenovo | Thinkcentre M90a Gen2 Firmware | All versions |
| Lenovo | Thinkcentre M820z Firmware | All versions |
| Lenovo | Ideacentre Aio 3-27itl6 Firmware | All versions |
| Lenovo | Ideacentre Aio 3-24itl6 Firmware | All versions |
| Lenovo | Thinkcentre M900x Firmware | All versions |
| Lenovo | Thinkcentre M800 Firmware | All versions |
| Lenovo | Ideacentre Aio 3-24iil5 Firmware | All versions |
| Lenovo | Thinkcentre M700 Firmware | All versions |
| Lenovo | Thinkcentre M700 Tiny Firmware | All versions |
| Lenovo | Ideacentre Aio 3-24ada6 Firmware | All versions |
| Lenovo | Ideacentre Aio 3-22itl6 Firmware | All versions |
| Lenovo | Ideacentre Aio 3-22iil5 Firmware | All versions |
| Lenovo | Ideacentre Aio 3-22ada6 Firmware | All versions |
| Lenovo | Ideacentre 5-14imb05 Firmware | All versions |
| Lenovo | Ideacentre C5-14imb05 Firmware | All versions |
References
- https://support.lenovo.com/us/en/product_security/LEN-77639Patch, Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-77639Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-4210?
How severe is CVE-2021-4210?
How do I fix CVE-2021-4210?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-42094An issue was discovered in Zammad before 4.1.1. Command Inje…9.8
- CVE-2021-42095Xshell before 7.0.0.76 allows attackers to cause a crash by …7.5
- CVE-2021-42096GNU Mailman before 2.1.35 may allow remote Privilege Escalat…4.3
- CVE-2021-42097GNU Mailman before 2.1.35 may allow remote Privilege Escalat…8
- CVE-2021-42098An incomplete permission check on entries in Devolutions Rem…8.8
- CVE-2021-42099Zoho ManageEngine M365 Manager Plus before 4421 is vulnerabl…9.8
- CVE-2021-42101An uncontrolled search path element vulnerabilities in Trend…7.8
- CVE-2021-42102An uncontrolled search path element vulnerabilities in Trend…7.8
- CVE-2021-42103An uncontrolled search path element vulnerabilities in Trend…7.8
- CVE-2021-42104Unnecessary privilege vulnerabilities in Trend Micro Apex On…7.8
- CVE-2021-42105Unnecessary privilege vulnerabilities in Trend Micro Apex On…7.8
- CVE-2021-42106Unnecessary privilege vulnerabilities in Trend Micro Apex On…7.8
Are you affected by CVE-2021-4210?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
