CVE-2021-4210

MEDIUMCVSS 6.7/10EPSS 0.24%

Last modified

CVE-2021-4210 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.

Description

A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.24%

15.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoStadia Ggp-120 FirmwareAll versions
LenovoThinkedge Se30 FirmwareAll versions
LenovoV540-24iwl FirmwareAll versions
LenovoThinkstation P520 FirmwareAll versions
LenovoThinkstation P310 FirmwareAll versions
LenovoV50t-13imb FirmwareAll versions
LenovoThinkstation P520c FirmwareAll versions
LenovoA540-27icb FirmwareAll versions
LenovoA540-24icb FirmwareAll versions
LenovoIdeacentre G5-14imb05 FirmwareAll versions
LenovoV410z FirmwareAll versions
LenovoThinkcentre M910z FirmwareAll versions
LenovoThinkcentre M70a FirmwareAll versions
LenovoThinkcentre M75n FirmwareAll versions
LenovoThinkcentre X1 FirmwareAll versions
LenovoThinkcentre M900 FirmwareAll versions
LenovoThinkcentre M810z FirmwareAll versions
LenovoThinkcentre M90a Gen2 FirmwareAll versions
LenovoThinkcentre M820z FirmwareAll versions
LenovoIdeacentre Aio 3-27itl6 FirmwareAll versions
LenovoIdeacentre Aio 3-24itl6 FirmwareAll versions
LenovoThinkcentre M900x FirmwareAll versions
LenovoThinkcentre M800 FirmwareAll versions
LenovoIdeacentre Aio 3-24iil5 FirmwareAll versions
LenovoThinkcentre M700 FirmwareAll versions
LenovoThinkcentre M700 Tiny FirmwareAll versions
LenovoIdeacentre Aio 3-24ada6 FirmwareAll versions
LenovoIdeacentre Aio 3-22itl6 FirmwareAll versions
LenovoIdeacentre Aio 3-22iil5 FirmwareAll versions
LenovoIdeacentre Aio 3-22ada6 FirmwareAll versions
LenovoIdeacentre 5-14imb05 FirmwareAll versions
LenovoIdeacentre C5-14imb05 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-4210?
A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
How severe is CVE-2021-4210?
CVE-2021-4210 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2021-4210?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-4210?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST