Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-8323


A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 6.4, requiring local system access to exploit but requires specific conditions to be met without requiring user interaction . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 344 products from lenovo, from lenovo, from lenovo and 341 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2020, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2020-06-09T20:15:22.427

Last Modified

2024-11-21T05:38:42.640

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.4 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System lenovo 330-14ast_firmware - Yes
Hardware lenovo 330-14ast - No
Operating System lenovo 330-15ast_firmware - Yes
Hardware lenovo 330-15ast - No
Operating System lenovo 330-17ast_firmware - Yes
Hardware lenovo 330-17ast - No
Operating System lenovo 340c-15api_firmware - Yes
Hardware lenovo 340c-15api - No
Operating System lenovo 340c-15ast_firmware - Yes
Hardware lenovo 340c-15ast - No
Operating System lenovo 720s_touch-15ikb_firmware - Yes
Hardware lenovo 720s_touch-15ikb - No
Operating System lenovo 720s-15ikb_firmware - Yes
Hardware lenovo 720s-15ikb - No
Operating System lenovo 730s-13iwl_firmware - Yes
Hardware lenovo 730s-13iwl - No
Operating System lenovo c640-iml_firmware - Yes
Hardware lenovo c640-iml - No
Operating System lenovo e42-80_firmware - Yes
Hardware lenovo e42-80 - No
Operating System lenovo e52-80_firmware - Yes
Hardware lenovo e52-80 - No
Operating System lenovo k22-80_firmware - Yes
Hardware lenovo k22-80 - No
Operating System lenovo v720-12_firmware - Yes
Hardware lenovo v720-12 - No
Operating System lenovo k32-80_kbl_firmware - Yes
Hardware lenovo k32-80_kbl - No
Operating System lenovo k32-80_skl_firmware - Yes
Hardware lenovo k32-80_skl - No
Operating System lenovo miix_720-12ikb_firmware - Yes
Hardware lenovo miix_720-12ikb - No
Operating System lenovo s145-14api_firmware - Yes
Hardware lenovo s145-14api - No
Operating System lenovo s145-14ast_firmware - Yes
Hardware lenovo s145-14ast - No
Operating System lenovo s145-15api_firmware - Yes
Hardware lenovo s145-15api - No
Operating System lenovo s145-15ast_firmware - Yes
Hardware lenovo s145-15ast - No
Operating System lenovo s540-13api_firmware - Yes
Hardware lenovo s540-13api - No
Operating System lenovo s750-iil_firmware - Yes
Hardware lenovo s750-iil - No
Operating System lenovo s940-14iwl_firmware - Yes
Hardware lenovo s940-14iwl - No
Operating System lenovo thinkbook_13s-iwl_firmware - Yes
Hardware lenovo thinkbook_13s-iwl - No
Operating System lenovo thinkbook_14s-iwl_firmware - Yes
Hardware lenovo thinkbook_14s-iwl - No
Operating System lenovo v110-14ast_firmware - Yes
Hardware lenovo v110-14ast - No
Operating System lenovo v110-14ikb_firmware - Yes
Hardware lenovo v110-14ikb - No
Operating System lenovo v110-15ast_firmware - Yes
Hardware lenovo v110-15ast - No
Operating System lenovo v130-15igm_firmware - Yes
Hardware lenovo v130-15igm - No
Operating System lenovo v130-15ikb_firmware - Yes
Hardware lenovo v130-15ikb - No
Operating System lenovo v310-15igm_firmware - Yes
Hardware lenovo v310-15igm - No
Operating System lenovo v330-15igm_firmware - Yes
Hardware lenovo v330-15igm - No
Operating System lenovo v330-15ikb_firmware - Yes
Hardware lenovo v330-15ikb - No
Operating System lenovo v330-15isk_firmware - Yes
Hardware lenovo v330-15isk - No
Operating System lenovo v340-iil_firmware - Yes
Hardware lenovo v340-iil - No
Operating System lenovo v340-iml_firmware - Yes
Hardware lenovo v340-iml - No
Operating System lenovo v540s-13_firmware - Yes
Hardware lenovo v540s-13 - No
Operating System lenovo 14iwl_firmware - Yes
Hardware lenovo 14iwl - No
Operating System lenovo v730-13ikb_firmware - Yes
Hardware lenovo v730-13ikb - No
Operating System lenovo v730-13isk_firmware - Yes
Hardware lenovo v730-13isk - No
Operating System lenovo v730-15ikb_firmware - Yes
Hardware lenovo v730-15ikb - No
Operating System lenovo wei5-15ikb_firmware - Yes
Hardware lenovo wei5-15ikb - No
Operating System lenovo xiaoxin_14-ast_qc_2019_firmware - Yes
Hardware lenovo xiaoxin_14-ast_qc_2019 - No
Operating System lenovo xx-14api_qc_2019_firmware - Yes
Hardware lenovo xx-14api_qc_2019 - No
Operating System lenovo yoga_s730-13iwl_firmware - Yes
Hardware lenovo yoga_s730-13iwl - No
Operating System lenovo yoga_s940-14iwl_firmware - Yes
Hardware lenovo yoga_s940-14iwl - No
Operating System lenovo 6_pro-13-iwl_firmware - Yes
Hardware lenovo 6_pro-13-iwl - No
Operating System lenovo 6_pro-14-iwl_firmware - Yes
Hardware lenovo 6_pro-14-iwl - No
Operating System lenovo e53-80_firmware - Yes
Hardware lenovo e53-80 - No
Operating System lenovo k3_firmware - Yes
Hardware lenovo k3 - No
Operating System lenovo k4-iwl_firmware - Yes
Hardware lenovo k4-iwl - No
Operating System lenovo thinkpad_11e_yoga_gen_6_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_11e_yoga_gen_6 - No
Operating System lenovo thinkpad_11e_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_11e - No
Operating System lenovo thinkpad_yoga_11e_3rd_gen_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_yoga_11e_3rd_gen - No
Operating System lenovo thinkpad_yoga_11e_4th_gen_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_yoga_11e_4th_gen - No
Operating System lenovo thinkpad_yoga_11e_5th_gen_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_yoga_11e_5th_gen - No
Operating System lenovo thinkpad_13_2nd_gen_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_13_2nd_gen - No
Operating System lenovo thinkpad_13_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_13 - No
Operating System lenovo thinkpad_a275_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_a275 - No
Operating System lenovo thinkpad_a285_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_a285 - No
Operating System lenovo thinkpad_a475_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_a475 - No
Operating System lenovo thinkpad_a485_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_a485 - No
Operating System lenovo thinkpad_e14_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e14 - No
Operating System lenovo thinkpad_e15_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e15 - No
Operating System lenovo thinkpad_r14_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_r14 - No
Operating System lenovo thinkpad_s3_gen_2_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_s3_gen_2 - No
Operating System lenovo thinkpad_e455_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e455 - No
Operating System lenovo thinkpad_e555_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e555 - No
Operating System lenovo thinkpad_e460_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e460 - No
Operating System lenovo thinkpad_e560_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e560 - No
Operating System lenovo thinkpad_e465_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e465 - No
Operating System lenovo thinkpad_e565_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e565 - No
Operating System lenovo thinkpad_e470_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e470 - No
Operating System lenovo thinkpad_e570_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e570 - No
Operating System lenovo thinkpad_e475_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e475 - No
Operating System lenovo thinkpad_e575_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e575 - No
Operating System lenovo thinkpad_e480_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e480 - No
Operating System lenovo thinkpad_e580_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e580 - No
Operating System lenovo thinkpad_e485_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e485 - No
Operating System lenovo thinkpad_e585_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e585 - No
Operating System lenovo thinkpad_e490s_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e490s - No
Operating System lenovo thinkpad_s3_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_s3 - No
Operating System lenovo thinkpad_e490_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e490 - No
Operating System lenovo thinkpad_e590_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e590 - No
Operating System lenovo thinkpad_r490_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_r490 - No
Operating System lenovo thinkpad_r590_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_r590 - No
Operating System lenovo thinkpad_l13_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l13 - No
Operating System lenovo thinkpad_l1415_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l1415 - No
Operating System lenovo thinkpad_l380_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l380 - No
Operating System lenovo thinkpad_s3_3rd_gen_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_s3_3rd_gen - No
Operating System lenovo thinkpad_l380_yoga_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l380_yoga - No
Operating System lenovo thinkpad_s2_yoga_3rd_gen_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_s2_yoga_3rd_gen - No
Operating System lenovo thinkpad_l390_yoga_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l390_yoga - No
Operating System lenovo thinkpad_s2_yoga_4th_gen_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_s2_yoga_4th_gen - No
Operating System lenovo thinkpad_l460_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l460 - No
Operating System lenovo thinkpad_l470_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l470 - No
Operating System lenovo thinkpad_l480_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l480 - No
Operating System lenovo thinkpad_l580_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l580 - No
Operating System lenovo thinkpad_l490_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l490 - No
Operating System lenovo thinkpad_l590_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l590 - No
Operating System lenovo thinkpad_l560_firmware < 2020-07-03 Yes
Hardware lenovo thinkpad_l560 - No
Operating System lenovo thinkpad_l570_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_l570 - No
Operating System lenovo thinkpad_p1_firmware < n2eet46w Yes
Hardware lenovo thinkpad_p1 - No
Operating System lenovo thinkpad_p43s_firmware < n2iet87w Yes
Hardware lenovo thinkpad_p43s - No
Operating System lenovo thinkpad_p50_firmware < 2020-07-17 Yes
Hardware lenovo thinkpad_p50 - No
Operating System lenovo thinkpad_p50s_firmware < 2020-07-24 Yes
Hardware lenovo thinkpad_p50s - No
Operating System lenovo thinkpad_p51_firmware < 2020-07-03 Yes
Hardware lenovo thinkpad_p51 - No
Operating System lenovo thinkpad_p51s_firmware < 2020-07-03 Yes
Hardware lenovo thinkpad_p51s - No
Operating System lenovo thinkpad_p52_firmware < n2cet51w Yes
Hardware lenovo thinkpad_p52 - No
Operating System lenovo thinkpad_p52s_firmware < 2020-07-03 Yes
Hardware lenovo thinkpad_p52s - No
Operating System lenovo thinkpad_p53_firmware < n2net37w Yes
Hardware lenovo thinkpad_p53 - No
Operating System lenovo thinkpad_p53s_firmware < n2iet87w Yes
Hardware lenovo thinkpad_p53s - No
Operating System lenovo thinkpad_p70_firmware < 2020-07-17 Yes
Hardware lenovo thinkpad_p70 - No
Operating System lenovo thinkpad_p71_firmware ≤ 2020-07-17 Yes
Hardware lenovo thinkpad_p71 - No
Operating System lenovo thinkpad_p72_firmware < n2cet51w Yes
Hardware lenovo thinkpad_p72 - No
Operating System lenovo thinkpad_p73_firmware < n2net37w Yes
Hardware lenovo thinkpad_p73 - No
Operating System lenovo thinkpad_s5_2nd_gen_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_s5_2nd_gen - No
Operating System lenovo thinkpad_s5_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_s5 - No
Operating System lenovo thinkpad_e560p_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_e560p - No
Operating System lenovo thinkpad_t25_firmware < n1qet87w Yes
Hardware lenovo thinkpad_t25 - No
Operating System lenovo thinkpad_t460_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_t460 - No
Operating System lenovo thinkpad_t460p_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_t460p - No
Operating System lenovo thinkpad_t460s_firmware < 2020-06-19 Yes
Hardware lenovo thinkpad_t460s - No
Operating System lenovo thinkpad_t470_firmware < n1qet87w Yes
Hardware lenovo thinkpad_t470 - No
Operating System lenovo thinkpad_t470p_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_t470p - No
Operating System lenovo thinkpad_t470s_firmware < n1wet58w Yes
Hardware lenovo thinkpad_t470s - No
Operating System lenovo thinkpad_t480_firmware < n24et56w Yes
Hardware lenovo thinkpad_t480 - No
Operating System lenovo thinkpad_t480s_firmware < n22et62w Yes
Hardware lenovo thinkpad_t480s - No
Operating System lenovo thinkpad_t490_firmware < n2iet87w Yes
Hardware lenovo thinkpad_t490 - No
Operating System lenovo thinkpad_t490s_firmware < n2jet87w Yes
Hardware lenovo thinkpad_t490s - No
Operating System lenovo thinkpad_t560_firmware < 2020-07-24 Yes
Hardware lenovo thinkpad_t560 - No
Operating System lenovo thinkpad_t570_firmware < 2020-07-03 Yes
Hardware lenovo thinkpad_t570 - No
Operating System lenovo thinkpad_t580_firmware < 2020-07-03 Yes
Hardware lenovo thinkpad_t580 - No
Operating System lenovo thinkpad_t590_firmware < n2iet87w Yes
Hardware lenovo thinkpad_t590 - No
Operating System lenovo thinkpad_x1_carbon_firmware < n1met60w Yes
Hardware lenovo thinkpad_x1_carbon - No
Operating System lenovo thinkpad_x1_yoga_firmware < 2020-07-17 Yes
Hardware lenovo thinkpad_x1_yoga - No
Operating System lenovo thinkpad_x1_extreme_firmware < n2oet43w Yes
Hardware lenovo thinkpad_x1_extreme - No
Operating System lenovo thinkpad_x1_tablet_firmware < 2020-07-24 Yes
Hardware lenovo thinkpad_x1_tablet - No
Operating System lenovo thinkpad_x1_yoga_firmware < 2020-07-17 Yes
Hardware lenovo thinkpad_x1_yoga - No
Operating System lenovo thinkpad_x260_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_x260 - No
Operating System lenovo thinkpad_x270_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_x270 - No
Operating System lenovo thinkpad_x280_firmware < n20et52w Yes
Hardware lenovo thinkpad_x280 - No
Operating System lenovo thinkpad_x380_yoga_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_x380_yoga - No
Operating System lenovo thinkpad_x390_firmware < 2020-07-07 Yes
Hardware lenovo thinkpad_x390 - No
Operating System lenovo thinkpad_x390_yoga_firmware < 2020-06-24 Yes
Hardware lenovo thinkpad_x390_yoga - No
Operating System lenovo thinkpad_x395_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_x395 - No
Operating System lenovo thinkpad_yoga_260_firmware < 2020-07-07 Yes
Hardware lenovo thinkpad_yoga_260 - No
Operating System lenovo thinkpad_s1_firmware < 2020-07-07 Yes
Hardware lenovo thinkpad_s1 - No
Operating System lenovo thinkpad_yoga_370_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_yoga_370 - No
Operating System lenovo thinkpad_s1_3rd_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_s1_3rd - No
Operating System lenovo thinkpad_t495_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_t495 - No
Operating System lenovo thinkpad_t495s_firmware < 2020-07-10 Yes
Hardware lenovo thinkpad_t495s - No
Operating System lenovo thinkpad_helix_firmware < n17etb2w Yes
Hardware lenovo thinkpad_helix - No
Operating System lenovo thinkpad_s1_yoga_firmware < gqet63ww Yes
Hardware lenovo thinkpad_s1_yoga - No
Operating System lenovo thinkpad_s1_yoga_vpro_firmware < b0et47ww Yes
Hardware lenovo thinkpad_s1_yoga_vpro - No
Operating System lenovo thinkpad_s5_yoga_15_firmware < n19et64w Yes
Hardware lenovo thinkpad_s5_yoga_15 - No
Operating System lenovo thinkpad_s540_firmware < gpet81ww Yes
Hardware lenovo thinkpad_s540 - No
Operating System lenovo thinkpad_t440_firmware < gjeta4ww Yes
Hardware lenovo thinkpad_t440 - No
Operating System lenovo thinkpad_t440s_firmware < gjeta4ww Yes
Hardware lenovo thinkpad_t440s - No
Operating System lenovo thinkpad_t440p_firmware < gleta1ww Yes
Hardware lenovo thinkpad_t440p - No
Operating System lenovo thinkpad_t540_firmware < gmet90ww Yes
Hardware lenovo thinkpad_t540 - No
Operating System lenovo thinkpad_t540p_firmware < gmet90ww Yes
Hardware lenovo thinkpad_t540p - No
Operating System lenovo thinkpad_t550_firmware < n11et52w Yes
Hardware lenovo thinkpad_t550 - No
Operating System lenovo thinkpad_w540_firmware < gnet93ww Yes
Hardware lenovo thinkpad_w540 - No
Operating System lenovo thinkpad_w541_firmware < gnet93ww Yes
Hardware lenovo thinkpad_w541 - No
Operating System lenovo thinkpad_w550s_firmware < n11et52w Yes
Hardware lenovo thinkpad_w550s - No
Operating System lenovo thinkpad_x1_carbon_\(20ax\)_firmware < gret63ww Yes
Hardware lenovo thinkpad_x1_carbon_\(20ax\) - No
Operating System lenovo thinkpad_x1_carbon_\(20bx\)_firmware < n14et54w Yes
Hardware lenovo thinkpad_x1_carbon_\(20bx\) - No
Operating System lenovo thinkpad_x140e_firmware < gset74ww Yes
Hardware lenovo thinkpad_x140e - No
Operating System lenovo thinkpad_x240_firmware < giet99ww Yes
Hardware lenovo thinkpad_x240 - No
Operating System lenovo thinkpad_x240s_firmware < giet99ww Yes
Hardware lenovo thinkpad_x240s - No
Operating System lenovo thinkpad_x250_firmware < n10et61w Yes
Hardware lenovo thinkpad_x250 - No
Operating System lenovo thinkpad_yoga_11e_\(20dx\)_firmware < n15et79w Yes
Hardware lenovo thinkpad_yoga_11e_\(20dx\) - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For lenovo's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.