CVE-2017-3775

Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.4 MEDIUM
PHYSICAL
HIGH
NONE
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
lenovoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
lenovoflex_system_x240_m5_bios
𝑥
< 2.61
lenovoflex_system_x280_x6_bios
𝑥
< 4.21
lenovoflex_system_x480_x6_bios
𝑥
< 4.21
lenovoflex_system_x880_bios
𝑥
< 4.21
lenovonextscale_nx360_m5_bios
𝑥
< 2.61
lenovosystem_x3250_m6_bios
𝑥
< 2.23
lenovosystem_x3500_m5_bios
𝑥
< 2.61
lenovosystem_x3550_m5_bios
𝑥
< 2.61
lenovosystem_x3650_m5_bios
𝑥
< 2.61
lenovosystem_x3850_x6_bios
𝑥
< 4.3
lenovosystem_x3950_x6_bios
𝑥
< 4.3
𝑥
= Vulnerable software versions