CVE-2021-4211
Last modified
CVE-2021-4211 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | A340-22icb Firmware | All versions |
| Lenovo | A340-22ick Firmware | All versions |
| Lenovo | A340-24icb Firmware | All versions |
| Lenovo | A340-24ick Firmware | All versions |
| Lenovo | A540-24icb Firmware | All versions |
| Lenovo | A540-27icb Firmware | All versions |
| Lenovo | Ideacentre 5-14iob6 Firmware | All versions |
| Lenovo | Ideacentre 510s-07icb Firmware | All versions |
| Lenovo | Ideacentre 510s-07ick Firmware | All versions |
| Lenovo | Ideacentre Aio 3-22ada6 Firmware | All versions |
| Lenovo | Ideacentre Aio 3-22iil5 Firmware | All versions |
| Lenovo | Ideacentre Aio 3-22itl6 Firmware | All versions |
| Lenovo | Ideacentre Aio 3-24ada6 Firmware | All versions |
| Lenovo | Ideacentre Aio 3-24iil5 Firmware | All versions |
| Lenovo | Ideacentre Aio 3-24itl6 Firmware | All versions |
| Lenovo | Ideacentre Aio 3-27itl6 Firmware | All versions |
| Lenovo | Ideacentre Creator 5-14iob6 Firmware | All versions |
| Lenovo | Ideacentre Gaming 5-14iob6 Firmware | All versions |
| Lenovo | Se30 Firmware | All versions |
| Lenovo | Thinkcentre M600 Firmware | All versions |
| Lenovo | Thinkcentre M700 Tiny Firmware | All versions |
| Lenovo | Thinkcentre M70a Firmware | All versions |
| Lenovo | Thinkcentre M710e Firmware | All versions |
| Lenovo | Thinkcentre M710q Firmware | All versions |
| Lenovo | Thinkcentre M710q \(10yc\) Firmware | All versions |
| Lenovo | Thinkcentre M710s Firmware | All versions |
| Lenovo | Thinkcentre M710t Firmware | All versions |
| Lenovo | Thinkcentre M720e Firmware | All versions |
| Lenovo | Thinkcentre M75n Firmware | All versions |
| Lenovo | Thinkcentre M800 Firmware | All versions |
| Lenovo | Thinkcentre M810z Firmware | All versions |
| Lenovo | Thinkcentre M820z Firmware | All versions |
| Lenovo | Thinkcentre M900 Firmware | All versions |
| Lenovo | Thinkcentre M900x Firmware | All versions |
| Lenovo | Thinkcentre M90a \(Gen 2\) Firmware | All versions |
| Lenovo | Thinkcentre M910q Firmware | All versions |
| Lenovo | Thinkcentre M910s Firmware | All versions |
| Lenovo | Thinkcentre M910t Firmware | All versions |
| Lenovo | Thinkcentre M910x Firmware | All versions |
| Lenovo | Thinkstation P310 Firmware | All versions |
| Lenovo | Thinkstation P320 Firmware | All versions |
| Lenovo | Thinkstation P320 Tiny Firmware | All versions |
| Lenovo | V30a-22iml Firmware | All versions |
| Lenovo | V30a-24iml Firmware | All versions |
| Lenovo | V410z Firmware | All versions |
| Lenovo | V50t-13iob G2 Firmware | All versions |
| Lenovo | V520 Firmware | All versions |
| Lenovo | V520s Firmware | All versions |
| Lenovo | V530-15icb Firmware | All versions |
| Lenovo | V530-15icr Firmware | All versions |
Showing 50 of 53 affected configurations. See NVD for the full list.
References
- https://support.lenovo.com/us/en/product_security/LEN-77639Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-77639Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-4211?
How severe is CVE-2021-4211?
How do I fix CVE-2021-4211?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-42104Unnecessary privilege vulnerabilities in Trend Micro Apex On…7.8
- CVE-2021-42105Unnecessary privilege vulnerabilities in Trend Micro Apex On…7.8
- CVE-2021-42106Unnecessary privilege vulnerabilities in Trend Micro Apex On…7.8
- CVE-2021-42107Unnecessary privilege vulnerabilities in Trend Micro Apex On…7.8
- CVE-2021-42108Unnecessary privilege vulnerabilities in the Web Console of …7.8
- CVE-2021-42109VITEC Exterity IPTV products through 2021-04-30 allow privil…9.8
- CVE-2021-42110An issue was discovered in Allegro Windows (formerly Popsy W…7.8
- CVE-2021-42111An issue was discovered in the RCDevs OpenOTP app 1.4.13 and…5.5
- CVE-2021-42112The "File upload question" functionality in LimeSurvey 3.x-L…6.1
- CVE-2021-42113An issue was discovered in StorageSecurityCommandDxe in Insy…8.2
- CVE-2021-42114Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vul…8.3
- CVE-2021-42115Missing HTTPOnly flag in Web Applications operating on Busin…9.1
Are you affected by CVE-2021-4211?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
