CVE Vulnerabilities

CVE-2020-8354

Published: Nov 11, 2020 | Modified: Nov 30, 2020
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution.

Affected Software

Name Vendor Start Version End Version
Notebook_firmware Lenovo - (including) - (including)

References