CVE-2024-45105
EUVD-2024-4131013.09.2024, 18:15
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| lenovo | thinkagile_hx5530_firmware | 𝑥 < afe130c | ADP |
| lenovo | thinkedge_se450__firmware | 𝑥 < cme116d | ADP |
| lenovo | thinkedge_se350_v2_firmware | 𝑥 < iye110f | ADP |
| lenovo | thinksystem_st250_v3_firmware | 𝑥 < cte110i | ADP |
| lenovo | thinkagile_hx3375_firmware | 𝑥 < d8e138d | ADP |
| lenovo | thinksystem_sr950_v3_firmware | 𝑥 < ebe108h | ADP |
| lenovo | thinkagile_hx650_v3_firmware | 𝑥 < ese126h | ADP |
| lenovo | thinksystem_sd530_v3_firmware | 𝑥 < fne118d | ADP |
| lenovo | thinkagile_hx645_v3_integrated_system_firmware | 𝑥 < kae120j | ADP |
| lenovo | thinksystem_sr850_v2_firmware | 𝑥 < m5e128i | ADP |
| lenovo | thinkedge_se455_v3_firmware | 𝑥 < mbe110h | ADP |
| lenovo | thinksystem_sd665_v3_firmware | 𝑥 < qge124h | ADP |
| lenovo | thinksystem_sr850_v3_firmware | 𝑥 < rse110h | ADP |
| lenovo | thinksystem_sr250_v2_firmware | 𝑥 < tqe116c | ADP |
| lenovo | thinksystem_sd630_v2_firmware | 𝑥 < u8e128l | ADP |
| lenovo | thinksystem_sd650_v3_firmware | 𝑥 < use130g | ADP |
Common Weakness Enumeration