CVE-2020-8333
Summary
| CVE | CVE-2020-8333 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-24 21:15:00 UTC |
| Updated | 2020-10-07 01:15:00 UTC |
| Description | A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | 63 | - | All | All | All |
| Hardware | Lenovo | 63 | - | All | All | All |
| Operating System | Lenovo | 63 Firmware | All | All | All | All |
| Operating System | Lenovo | 63 Firmware | All | All | All | All |
| Hardware | Lenovo | H50-30g | - | All | All | All |
| Hardware | Lenovo | H50-30g | - | All | All | All |
| Operating System | Lenovo | H50-30g Firmware | All | All | All | All |
| Operating System | Lenovo | H50-30g Firmware | All | All | All | All |
| Hardware | Lenovo | M4500 | - | All | All | All |
| Hardware | Lenovo | M4500 | - | All | All | All |
| Operating System | Lenovo | M4500 Firmware | All | All | All | All |
| Operating System | Lenovo | M4500 Firmware | All | All | All | All |
| Hardware | Lenovo | M4550 | - | All | All | All |
| Hardware | Lenovo | M4550 | - | All | All | All |
| Operating System | Lenovo | M4550 Firmware | All | All | All | All |
| Operating System | Lenovo | M4550 Firmware | All | All | All | All |
| Hardware | Lenovo | Qitian 4500 | - | All | All | All |
| Hardware | Lenovo | Qitian 4500 | - | All | All | All |
| Operating System | Lenovo | Qitian 4500 Firmware | All | All | All | All |
| Operating System | Lenovo | Qitian 4500 Firmware | All | All | All | All |
| Hardware | Lenovo | Qitian B4550 | - | All | All | All |
| Hardware | Lenovo | Qitian B4550 | - | All | All | All |
| Operating System | Lenovo | Qitian B4550 Firmware | All | All | All | All |
| Operating System | Lenovo | Qitian B4550 Firmware | All | All | All | All |
| Hardware | Lenovo | Qitian M4550 | - | All | All | All |
| Hardware | Lenovo | Qitian M4550 | - | All | All | All |
| Operating System | Lenovo | Qitian M4550 Firmware | All | All | All | All |
| Operating System | Lenovo | Qitian M4550 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkcentre E73 | - | All | All | All |
| Hardware | Lenovo | Thinkcentre E73 | - | All | All | All |
| Hardware | Lenovo | Thinkcentre E73s | - | All | All | All |
| Hardware | Lenovo | Thinkcentre E73s | - | All | All | All |
| Operating System | Lenovo | Thinkcentre E73s Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkcentre E73s Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkcentre E73 Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkcentre E73 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkcentre E93 | - | All | All | All |
| Hardware | Lenovo | Thinkcentre E93 | - | All | All | All |
| Operating System | Lenovo | Thinkcentre E93 Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkcentre E93 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkcentre M4500k | - | All | All | All |
| Hardware | Lenovo | Thinkcentre M4500k | - | All | All | All |
| Operating System | Lenovo | Thinkcentre M4500k Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkcentre M4500k Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkcentre M4500q | - | All | All | All |
| Hardware | Lenovo | Thinkcentre M4500q | - | All | All | All |
| Operating System | Lenovo | Thinkcentre M4500q Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkcentre M4500q Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkcentre M4500s | - | All | All | All |
| Hardware | Lenovo | Thinkcentre M4500s | - | All | All | All |
| Operating System | Lenovo | Thinkcentre M4500s Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkcentre M4500s Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkcentre M4500t | - | All | All | All |
| Hardware | Lenovo | Thinkcentre M4500t | - | All | All | All |
| Operating System | Lenovo | Thinkcentre M4500t Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkcentre M4500t Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkcentre M9350z | - | All | All | All |
| Hardware | Lenovo | Thinkcentre M9350z | - | All | All | All |
| Operating System | Lenovo | Thinkcentre M9350z Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkcentre M9350z Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkcentre M93z | - | All | All | All |
| Hardware | Lenovo | Thinkcentre M93z | - | All | All | All |
| Operating System | Lenovo | Thinkcentre M93z Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkcentre M93z Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkstation C30 | - | All | All | All |
| Hardware | Lenovo | Thinkstation C30 | - | All | All | All |
| Operating System | Lenovo | Thinkstation C30 Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkstation C30 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkstation D30 | - | All | All | All |
| Hardware | Lenovo | Thinkstation D30 | - | All | All | All |
| Operating System | Lenovo | Thinkstation D30 Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkstation D30 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkstation E32 | - | All | All | All |
| Hardware | Lenovo | Thinkstation E32 | - | All | All | All |
| Operating System | Lenovo | Thinkstation E32 Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkstation E32 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkstation P300 | - | All | All | All |
| Hardware | Lenovo | Thinkstation P300 | - | All | All | All |
| Operating System | Lenovo | Thinkstation P300 Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkstation P300 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkstation S30 | - | All | All | All |
| Hardware | Lenovo | Thinkstation S30 | - | All | All | All |
| Operating System | Lenovo | Thinkstation S30 Firmware | All | All | All | All |
| Operating System | Lenovo | Thinkstation S30 Firmware | All | All | All | All |
| Hardware | Lenovo | Yangtian Afh81 | - | All | All | All |
| Hardware | Lenovo | Yangtian Afh81 | - | All | All | All |
| Operating System | Lenovo | Yangtian Afh81 Firmware | All | All | All | All |
| Operating System | Lenovo | Yangtian Afh81 Firmware | All | All | All | All |
| Hardware | Lenovo | Yangtian Mc H81 | - | All | All | All |
| Hardware | Lenovo | Yangtian Mc H81 | - | All | All | All |
| Operating System | Lenovo | Yangtian Mc H81 Firmware | All | All | All | All |
| Operating System | Lenovo | Yangtian Mc H81 Firmware | All | All | All | All |
| Hardware | Lenovo | Yangtian Mf H81 Pci | - | All | All | All |
| Hardware | Lenovo | Yangtian Mf H81 Pci | - | All | All | All |
| Operating System | Lenovo | Yangtian Mf H81 Pci Firmware | All | All | All | All |
| Operating System | Lenovo | Yangtian Mf H81 Pci Firmware | All | All | All | All |
| Hardware | Lenovo | Yangtian Tc H81 Pci | - | All | All | All |
| Hardware | Lenovo | Yangtian Tc H81 Pci | - | All | All | All |
| Operating System | Lenovo | Yangtian Tc H81 Pci Firmware | All | All | All | All |
| Operating System | Lenovo | Yangtian Tc H81 Pci Firmware | All | All | All | All |
| Hardware | Lenovo | Yangtian Wcc H81 Pci | - | All | All | All |
| Hardware | Lenovo | Yangtian Wcc H81 Pci | - | All | All | All |
| Operating System | Lenovo | Yangtian Wcc H81 Pci Firmware | All | All | All | All |
| Operating System | Lenovo | Yangtian Wcc H81 Pci Firmware | All | All | All | All |
| Hardware | Lenovo | Yangtian Wf H81 Pci | - | All | All | All |
| Hardware | Lenovo | Yangtian Wf H81 Pci | - | All | All | All |
| Operating System | Lenovo | Yangtian Wf H81 Pci Firmware | All | All | All | All |
| Operating System | Lenovo | Yangtian Wf H81 Pci Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multi-vendor BIOS Security Vulnerabilities (June 2020) - US | CONFIRM | support.lenovo.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Lenovo thanks yngwei (@yngweijw), driedfish (@d3af1sh), and MengHao, Li of IIE VARAS
There are currently no legacy QID mappings associated with this CVE.